Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978AB7C0 FindFirstFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00007FF7978AB7C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B72A8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime, |
0_2_00007FF7978B72A8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B71F4 FindFirstFileW,FindClose, |
0_2_00007FF7978B71F4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978ABC70 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00007FF7978ABC70 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA874 FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00007FF7978BA874 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978AC7C0 lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00007FF7978AC7C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA4F8 FindFirstFileW,FindNextFileW,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose, |
0_2_00007FF7978BA4F8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B6428 FindFirstFileW,FindNextFileW,FindClose, |
0_2_00007FF7978B6428 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA350 FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose, |
0_2_00007FF7978BA350 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797872F50 FindFirstFileExW, |
0_2_00007FF797872F50 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
3_2_004C4005 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C494A GetFileAttributesW,FindFirstFileW,FindClose, |
3_2_004C494A |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
3_2_004CC2FF |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CCD14 FindFirstFileW,FindClose, |
3_2_004CCD14 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
3_2_004CCD9F |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
3_2_004CF5D8 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
3_2_004CF735 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
3_2_004CFA36 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
3_2_004C3CE2 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F84005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
8_2_00F84005 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8494A GetFileAttributesW,FindFirstFileW,FindClose, |
8_2_00F8494A |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
8_2_00F8C2FF |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
8_2_00F8CD9F |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8CD14 FindFirstFileW,FindClose, |
8_2_00F8CD14 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
8_2_00F8F5D8 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
8_2_00F8F735 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
8_2_00F8FA36 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F83CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
8_2_00F83CE2 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D887000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://my.cloudme.com |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71DC7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1822512403.000001C72C304000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C4B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D8F2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C4B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2033706127.000001C734A92000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2950931190.0000000000529000.00000002.00000001.01000000.00000007.sdmp |
String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000001.00000002.1822512403.000001C72C304000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000001.00000002.1822512403.000001C72C304000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000001.00000002.1822512403.000001C72C304000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C4B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D11F000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000001.00000002.2021600603.000001C73479E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://go.microsoft.co- |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D11F000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://my.cloH |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D11F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1809510030.000001C71C4B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://my.cloudme.com |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71C4B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://my.cloudme.com/v1/ws2/:updatemake/:reality/reality.txt |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71DC7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1822512403.000001C72C304000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D8F2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://oneget.org |
Source: powershell.exe, 00000001.00000002.1809510030.000001C71D8F2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://oneget.orgX |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: file.exe, 00000000.00000003.1700160371.000002B512254000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1693624835.000002B51232E000.00000004.00000020.00020000.00000000.sdmp, InformationCheck.exe, 00000003.00000002.2956313395.0000000004AE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004ED164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
3_2_004ED164 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00FAD164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
8_2_00FAD164 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978CF630 |
0_2_00007FF7978CF630 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797842E30 |
0_2_00007FF797842E30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978458D0 |
0_2_00007FF7978458D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79785F8D0 |
0_2_00007FF79785F8D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79783183C |
0_2_00007FF79783183C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797871840 |
0_2_00007FF797871840 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978AD87C |
0_2_00007FF7978AD87C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978E17C0 |
0_2_00007FF7978E17C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797861750 |
0_2_00007FF797861750 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C56A0 |
0_2_00007FF7978C56A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978695B0 |
0_2_00007FF7978695B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79783B390 |
0_2_00007FF79783B390 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C32AC |
0_2_00007FF7978C32AC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79787529C |
0_2_00007FF79787529C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C206C |
0_2_00007FF7978C206C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797835F3C |
0_2_00007FF797835F3C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79785BEB4 |
0_2_00007FF79785BEB4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79783BE70 |
0_2_00007FF79783BE70 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797843C20 |
0_2_00007FF797843C20 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978DDB18 |
0_2_00007FF7978DDB18 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B1A18 |
0_2_00007FF7978B1A18 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79784FA4F |
0_2_00007FF79784FA4F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79783B9F0 |
0_2_00007FF79783B9F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978DBA0C |
0_2_00007FF7978DBA0C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79786793C |
0_2_00007FF79786793C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79786A8A0 |
0_2_00007FF79786A8A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978767F0 |
0_2_00007FF7978767F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978DC6D4 |
0_2_00007FF7978DC6D4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978DA59C |
0_2_00007FF7978DA59C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978D055C |
0_2_00007FF7978D055C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978684C0 |
0_2_00007FF7978684C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797854514 |
0_2_00007FF797854514 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B83D4 |
0_2_00007FF7978B83D4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79785C3FC |
0_2_00007FF79785C3FC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797872400 |
0_2_00007FF797872400 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C6320 |
0_2_00007FF7978C6320 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C8360 |
0_2_00007FF7978C8360 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978502C4 |
0_2_00007FF7978502C4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF79785C130 |
0_2_00007FF79785C130 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978630DC |
0_2_00007FF7978630DC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797840E70 |
0_2_00007FF797840E70 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978DCE8C |
0_2_00007FF7978DCE8C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797850E90 |
0_2_00007FF797850E90 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797876DE4 |
0_2_00007FF797876DE4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797872D20 |
0_2_00007FF797872D20 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978C6C34 |
0_2_00007FF7978C6C34 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978D0AEC |
0_2_00007FF7978D0AEC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797832AE0 |
0_2_00007FF797832AE0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0046B020 |
3_2_0046B020 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004694E0 |
3_2_004694E0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00469C80 |
3_2_00469C80 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004823F5 |
3_2_004823F5 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004E8400 |
3_2_004E8400 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00496502 |
3_2_00496502 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0049265E |
3_2_0049265E |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0046E6F0 |
3_2_0046E6F0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0048282A |
3_2_0048282A |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004989BF |
3_2_004989BF |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00496A74 |
3_2_00496A74 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004E0A3A |
3_2_004E0A3A |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00470BE0 |
3_2_00470BE0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0048CD51 |
3_2_0048CD51 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004BEDB2 |
3_2_004BEDB2 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C8E44 |
3_2_004C8E44 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004E0EB7 |
3_2_004E0EB7 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00496FE6 |
3_2_00496FE6 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004833B7 |
3_2_004833B7 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0047D45D |
3_2_0047D45D |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0048F409 |
3_2_0048F409 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00461663 |
3_2_00461663 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0047F628 |
3_2_0047F628 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0046F6A0 |
3_2_0046F6A0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004816B4 |
3_2_004816B4 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004878C3 |
3_2_004878C3 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00481BA8 |
3_2_00481BA8 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0048DBA5 |
3_2_0048DBA5 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00499CE5 |
3_2_00499CE5 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0047DD28 |
3_2_0047DD28 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00481FC0 |
3_2_00481FC0 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_0048BFD6 |
3_2_0048BFD6 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F2B020 |
8_2_00F2B020 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F294E0 |
8_2_00F294E0 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F29C80 |
8_2_00F29C80 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F423F5 |
8_2_00F423F5 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00FA8400 |
8_2_00FA8400 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F56502 |
8_2_00F56502 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F2E6F0 |
8_2_00F2E6F0 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F5265E |
8_2_00F5265E |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F4282A |
8_2_00F4282A |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F589BF |
8_2_00F589BF |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F56A74 |
8_2_00F56A74 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00FA0A3A |
8_2_00FA0A3A |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F30BE0 |
8_2_00F30BE0 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F7EDB2 |
8_2_00F7EDB2 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F4CD51 |
8_2_00F4CD51 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00FA0EB7 |
8_2_00FA0EB7 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F88E44 |
8_2_00F88E44 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F56FE6 |
8_2_00F56FE6 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F433B7 |
8_2_00F433B7 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F3D45D |
8_2_00F3D45D |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F4F409 |
8_2_00F4F409 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F416B4 |
8_2_00F416B4 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F2F6A0 |
8_2_00F2F6A0 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F21663 |
8_2_00F21663 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F3F628 |
8_2_00F3F628 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F478C3 |
8_2_00F478C3 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F4DBA5 |
8_2_00F4DBA5 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F41BA8 |
8_2_00F41BA8 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F59CE5 |
8_2_00F59CE5 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F3DD28 |
8_2_00F3DD28 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F4BFD6 |
8_2_00F4BFD6 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F41FC0 |
8_2_00F41FC0 |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: jscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: twext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cscui.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797854514 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
0_2_00007FF797854514 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004E59B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
3_2_004E59B3 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_00475EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
3_2_00475EDA |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00FA59B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
8_2_00FA59B3 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F35EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
8_2_00F35EDA |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\Public\InformationCheck.exe |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978AB7C0 FindFirstFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00007FF7978AB7C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B72A8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime, |
0_2_00007FF7978B72A8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B71F4 FindFirstFileW,FindClose, |
0_2_00007FF7978B71F4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978ABC70 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00007FF7978ABC70 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA874 FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00007FF7978BA874 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978AC7C0 lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00007FF7978AC7C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA4F8 FindFirstFileW,FindNextFileW,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose, |
0_2_00007FF7978BA4F8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978B6428 FindFirstFileW,FindNextFileW,FindClose, |
0_2_00007FF7978B6428 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF7978BA350 FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose, |
0_2_00007FF7978BA350 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00007FF797872F50 FindFirstFileExW, |
0_2_00007FF797872F50 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
3_2_004C4005 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C494A GetFileAttributesW,FindFirstFileW,FindClose, |
3_2_004C494A |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
3_2_004CC2FF |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CCD14 FindFirstFileW,FindClose, |
3_2_004CCD14 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
3_2_004CCD9F |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
3_2_004CF5D8 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
3_2_004CF735 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004CFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
3_2_004CFA36 |
Source: C:\Users\Public\InformationCheck.exe |
Code function: 3_2_004C3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
3_2_004C3CE2 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F84005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
8_2_00F84005 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8494A GetFileAttributesW,FindFirstFileW,FindClose, |
8_2_00F8494A |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
8_2_00F8C2FF |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
8_2_00F8CD9F |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8CD14 FindFirstFileW,FindClose, |
8_2_00F8CD14 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
8_2_00F8F5D8 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
8_2_00F8F735 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F8FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
8_2_00F8FA36 |
Source: C:\Users\user\AppData\Local\WordGenius Technologies\SwiftWrite.pif |
Code function: 8_2_00F83CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
8_2_00F83CE2 |