Windows Analysis Report
https://s3.us-east-2.amazonaws.com/revealedgceconomies/vdiq197yvi/ImgBurn_822881.exe?

Overview

General Information

Sample URL: https://s3.us-east-2.amazonaws.com/revealedgceconomies/vdiq197yvi/ImgBurn_822881.exe?
Analysis ID: 1538468
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for dropped file
Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory

Classification

AV Detection

barindex
Source: C:\Users\user\Downloads\Unconfirmed 50026.crdownload ReversingLabs: Detection: 37%
Source: C:\Users\user\Downloads\Unconfirmed 50026.crdownload Virustotal: Detection: 35% Perma Link
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.5.9:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.5.9:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.1.33.206:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 51.104.15.253:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49757 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49758 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49759 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49762 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 51.104.15.253:443 -> 192.168.2.16:49760 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49764 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49765 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.16:49769 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.254:443 -> 192.168.2.16:49772 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.254:443 -> 192.168.2.16:49774 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: C:\Windows\System32\unregmp2.exe File opened: z:
Source: C:\Windows\System32\unregmp2.exe File opened: x:
Source: C:\Windows\System32\unregmp2.exe File opened: v:
Source: C:\Windows\System32\unregmp2.exe File opened: t:
Source: C:\Windows\System32\unregmp2.exe File opened: r:
Source: C:\Windows\System32\unregmp2.exe File opened: p:
Source: C:\Windows\System32\unregmp2.exe File opened: n:
Source: C:\Windows\System32\unregmp2.exe File opened: l:
Source: C:\Windows\System32\unregmp2.exe File opened: j:
Source: C:\Windows\System32\unregmp2.exe File opened: h:
Source: C:\Windows\System32\unregmp2.exe File opened: f:
Source: C:\Windows\System32\unregmp2.exe File opened: b:
Source: C:\Windows\System32\unregmp2.exe File opened: y:
Source: C:\Windows\System32\unregmp2.exe File opened: w:
Source: C:\Windows\System32\unregmp2.exe File opened: u:
Source: C:\Windows\System32\unregmp2.exe File opened: s:
Source: C:\Windows\System32\unregmp2.exe File opened: q:
Source: C:\Windows\System32\unregmp2.exe File opened: o:
Source: C:\Windows\System32\unregmp2.exe File opened: m:
Source: C:\Windows\System32\unregmp2.exe File opened: k:
Source: C:\Windows\System32\unregmp2.exe File opened: i:
Source: C:\Windows\System32\unregmp2.exe File opened: g:
Source: C:\Windows\System32\unregmp2.exe File opened: e:
Source: C:\Windows\System32\unregmp2.exe File opened: c:
Source: C:\Windows\System32\unregmp2.exe File opened: a:
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft\Media Player
Source: chrome.exe Memory has grown: Private usage: 1MB later: 33MB
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global traffic DNS traffic detected: DNS query: s3.us-east-2.amazonaws.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: contentworldinc.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 49681 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49683 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.5.9:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.5.9:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.1.33.206:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 51.104.15.253:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49757 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49758 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49759 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49762 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 51.104.15.253:443 -> 192.168.2.16:49760 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49764 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49765 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.16:49769 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.254:443 -> 192.168.2.16:49772 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.254:443 -> 192.168.2.16:49774 version: TLS 1.2
Source: unknown HTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: classification engine Classification label: mal48.win@45/38@6/102
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\a95add7b-c53e-41f4-88a5-4e133f87320a.tmp
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\Microsoft_WMP_70_CheckForOtherInstanceMutex
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Users\user\AppData\Local\Temp\msdt
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Users\user\Desktop\desktop.ini
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://s3.us-east-2.amazonaws.com/revealedgceconomies/vdiq197yvi/ImgBurn_822881.exe?"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4856 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4856 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5384 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ImgBurn_822881.exe "C:\Users\user\Downloads\ImgBurn_822881.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5384 --field-trial-handle=1972,i,8619648586621712017,6732439371838954860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ImgBurn_822881.exe "C:\Users\user\Downloads\ImgBurn_822881.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ImgBurn_822881.exe "C:\Users\user\Downloads\ImgBurn_822881.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ImgBurn_822881.exe "C:\Users\user\Downloads\ImgBurn_822881.exe"
Source: unknown Process created: C:\Program Files (x86)\Windows Media Player\wmplayer.exe "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:1
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\unregmp2.exe "C:\Windows\System32\unregmp2.exe" /AsyncFirstLogon
Source: C:\Windows\SysWOW64\unregmp2.exe Process created: C:\Windows\System32\unregmp2.exe "C:\Windows\SysNative\unregmp2.exe" /AsyncFirstLogon /REENTRANT
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\unregmp2.exe "C:\Windows\System32\unregmp2.exe" /AsyncFirstLogon
Source: C:\Windows\SysWOW64\unregmp2.exe Process created: C:\Windows\System32\unregmp2.exe "C:\Windows\SysNative\unregmp2.exe" /AsyncFirstLogon /REENTRANT
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wldp.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: explorerframe.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: textshaping.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: sspicli.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: secur32.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: mswsock.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: dnsapi.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: schannel.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ntasn1.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ncrypt.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wldp.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: explorerframe.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: textshaping.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: sspicli.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: secur32.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: mswsock.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: dnsapi.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: schannel.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ntasn1.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ncrypt.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: propsys.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: edputil.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: appresolver.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: bcp47langs.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: slc.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: sppc.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: gnsdk_fp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmvcore.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mfperfhelper.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmasf.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmploc.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: atlthunk.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: jscript.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windowscodecs.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: msimg32.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mmdevapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: devobj.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mfplat.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rtworkq.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: audioses.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: powrprof.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: umpdc.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windows.ui.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windowmanagementapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: inputhost.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: netprofm.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: npmproxy.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dataexchange.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dcomp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winsta.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: imapi2.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mswmdm.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cewmdm.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: upnp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ssdpapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmdmps.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: explorerframe.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: linkinfo.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ntshrui.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cscapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: policymanager.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmpps.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: propsys.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: edputil.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: urlmon.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: iertutil.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: appresolver.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: bcp47langs.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: slc.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: sppc.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Windows\SysWOW64\unregmp2.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: version.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmp.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmvcore.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: dwmapi.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: mfperfhelper.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmasf.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmploc.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: mmdevapi.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: devobj.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: mfplat.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: rtworkq.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: audioses.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: windows.ui.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: windowmanagementapi.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: inputhost.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: propsys.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: mlang.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: winmm.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmnetmgr.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wldp.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: profapi.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: secur32.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: msv1_0.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: ntlmshared.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: cryptdll.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wdigest.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: netutils.dll
Source: C:\Windows\System32\unregmp2.exe Section loaded: wmpps.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windows.security.authentication.onlineid.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dpapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: onesettingsclient.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: webio.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cryptnet.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: comppkgsup.dll
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: xmllite.dll
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32
Source: C:\Windows\SysWOW64\msdt.exe File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\a95add7b-c53e-41f4-88a5-4e133f87320a.tmp Jump to dropped file
Source: C:\Users\user\Downloads\ImgBurn_822881.exe File created: C:\Users\user\AppData\Local\MPC-HC\MPC-HC.1.9.19.x86.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Users\user\AppData\Local\Temp\SDIAG_628502e2-7a7f-489c-9d3e-1258e5fc3883\en-GB\DiagPackage.dll.mui Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\Unconfirmed 50026.crdownload Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Users\user\AppData\Local\Temp\SDIAG_628502e2-7a7f-489c-9d3e-1258e5fc3883\DiagPackage.dll Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\unregmp2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\MPC-HC\MPC-HC.1.9.19.x86.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\SDIAG_628502e2-7a7f-489c-9d3e-1258e5fc3883\en-GB\DiagPackage.dll.mui Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\SDIAG_628502e2-7a7f-489c-9d3e-1258e5fc3883\DiagPackage.dll Jump to dropped file
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local
Source: C:\Windows\System32\unregmp2.exe File opened: C:\Users\user\AppData\Local\Microsoft\Media Player
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Process information queried: ProcessInformation
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Process token adjusted: Debug
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Process token adjusted: Debug
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Process token adjusted: Debug
Source: C:\Users\user\Downloads\ImgBurn_822881.exe Process token adjusted: Debug
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\unregmp2.exe "C:\Windows\System32\unregmp2.exe" /AsyncFirstLogon
Source: C:\Windows\SysWOW64\unregmp2.exe Process created: C:\Windows\System32\unregmp2.exe "C:\Windows\SysNative\unregmp2.exe" /AsyncFirstLogon /REENTRANT
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: \Device\CdRom0\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\SysWOW64\msdt.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat VolumeInformation
Source: C:\Windows\System32\unregmp2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs