Windows Analysis Report
StrCmp.7z

Overview

General Information

Sample name: StrCmp.7z
Analysis ID: 1538458
MD5: 6b66077329b871ffb9acd8d380c32620
SHA1: 97a1fa8230100ab247555f09dafa76146f740163
SHA256: 948b664b1e308d8472f1f0f2b61db8bd9b42eca291db93dced4ed3db1de2c1af
Infos:

Detection

Score: 22
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Sigma detected: Potential Persistence Via COM Hijacking From Suspicious Locations
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Drops PE files
Queries the volume information (name, serial number etc) of a device

Classification

Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: tse1.mm.bing.net
Source: C:\Program Files\7-Zip\7zFM.exe Window created: window name: CLIPBRDWNDCLASS
Source: classification engine Classification label: sus22.win7Z@14/3@1/0
Source: C:\Program Files\7-Zip\7zFM.exe File created: C:\Users\user\Desktop\StrCmp.exe
Source: C:\Users\user\Desktop\StrCmp.exe Mutant created: NULL
Source: C:\Windows\System32\OpenWith.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2860:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6520:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7072:120:WilError_03
Source: C:\Program Files\7-Zip\7zFM.exe File created: C:\Users\user\AppData\Local\Temp\7zE8AF93B19
Source: C:\Windows\System32\OpenWith.exe File read: C:\Users\desktop.ini
Source: C:\Windows\System32\OpenWith.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Windows\System32\OpenWith.exe Process created: C:\Program Files\7-Zip\7z.exe "C:\Program Files\7-Zip\7z.exe" "C:\Users\user\Desktop\StrCmp.7z"
Source: C:\Program Files\7-Zip\7z.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\OpenWith.exe Process created: C:\Program Files\7-Zip\7z.exe "C:\Program Files\7-Zip\7z.exe" "C:\Users\user\Desktop\StrCmp.7z"
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Program Files\7-Zip\7z.exe "C:\Program Files\7-Zip\7z.exe" "C:\Users\user\Desktop\StrCmp.7z"
Source: C:\Program Files\7-Zip\7z.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\SystemSettingsBroker.exe C:\Windows\System32\SystemSettingsBroker.exe -Embedding
Source: unknown Process created: C:\Program Files\7-Zip\7zFM.exe "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\user\Desktop\StrCmp.7z"
Source: C:\Program Files\7-Zip\7zFM.exe Process created: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe "C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe"
Source: C:\Program Files\7-Zip\7zFM.exe Process created: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe "C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe"
Source: unknown Process created: C:\Users\user\Desktop\StrCmp.exe "C:\Users\user\Desktop\StrCmp.exe"
Source: unknown Process created: C:\Users\user\Desktop\StrCmp.exe "C:\Users\user\Desktop\StrCmp.exe"
Source: unknown Process created: C:\Users\user\Desktop\StrCmp.exe "C:\Users\user\Desktop\StrCmp.exe"
Source: C:\Windows\System32\OpenWith.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: wldp.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinui.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dwmapi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: pdh.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: actxprxy.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: propsys.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.appdefaults.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.immersive.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: profapi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: uiautomationcore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dui70.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: duser.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dwrite.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: bcp47mrm.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: uianimation.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: d3d11.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dxgi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: d3d10warp.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: resourcepolicyclient.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dxcore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dcomp.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: oleacc.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: edputil.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windowmanagementapi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: inputhost.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windowscodecs.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: thumbcache.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: appresolver.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: bcp47langs.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: slc.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: userenv.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: sppc.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: tiledatarepository.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: staterepository.core.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepository.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: wtsapi32.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepositorycore.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: mrmcorer.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: sxs.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: directmanipulation.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: ninput.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: explorerframe.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: dataexchange.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.fileexplorer.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: xmllite.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: structuredquery.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: atlthunk.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.fileexplorer.common.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.storage.search.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: linkinfo.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinapi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: ntshrui.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: cscapi.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: winmm.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: ehstorshell.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: cscui.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: networkexplorer.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: netutils.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: mpr.dll
Source: C:\Windows\System32\OpenWith.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: systemsettings.datamodel.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: settingshandlers_sharedexperiences_rome.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: wldp.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: windows.devices.radios.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: cdp.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: propsys.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: dsreg.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\SystemSettingsBroker.exe Section loaded: policymanager.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: uxtheme.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: textshaping.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: windows.storage.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: wldp.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: windowscodecs.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: profapi.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: propsys.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: explorerframe.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: cryptbase.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: thumbcache.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: textinputframework.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: coremessaging.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: ntmarta.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: wintypes.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: wintypes.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: wintypes.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: dataexchange.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: d3d11.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: dcomp.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: dxgi.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: policymanager.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: edputil.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: urlmon.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: iertutil.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: srvcli.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: netutils.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: sspicli.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: appresolver.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: bcp47langs.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: slc.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: userenv.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: sppc.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: apphelp.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: pcacli.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: mpr.dll
Source: C:\Program Files\7-Zip\7zFM.exe Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: msvbvm60.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: vb6zz.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: msvbvm60.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: vb6zz.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: msvbvm60.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: vb6zz.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: msvbvm60.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: vb6zz.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\StrCmp.exe Section loaded: sxs.dll
Source: C:\Windows\System32\OpenWith.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\System32\OpenWith.exe Window detected: Number of UI elements: 13
Source: C:\Program Files\7-Zip\7zFM.exe File created: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Jump to dropped file
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\SystemSettingsBroker.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\7-Zip\7zFM.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\7zO8AFC0119\StrCmp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\StrCmp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\StrCmp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\StrCmp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\7-Zip\7zFM.exe Process information queried: ProcessInformation
Source: C:\Windows\System32\OpenWith.exe Process created: C:\Program Files\7-Zip\7z.exe "C:\Program Files\7-Zip\7z.exe" "C:\Users\user\Desktop\StrCmp.7z"
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformation
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformation
⊘No contacted IP infos