Windows Analysis Report
hAyQbTcI0I.exe

Overview

General Information

Sample name: hAyQbTcI0I.exe
renamed because original name is a hash value
Original sample name: 08b4f4533262033c2a77f079c9c72949.exe
Analysis ID: 1540829
MD5: 08b4f4533262033c2a77f079c9c72949
SHA1: 4f82986f1c055d475374b4f6168f7a7bcdcfe50a
SHA256: 5b9c4eb3b57004c472245f3483fe5065f47b992543ff0d7ce3aaf100ab59088f
Tags: exeSocks5Systemzuser-abuse_ch
Infos:

Detection

Socks5Systemz
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Socks5Systemz
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to infect the boot sector
Machine Learning detection for dropped file
Binary contains a suspicious time stamp
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Entry point lies outside standard sections
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Sample file is different than original file name gathered from version info
Sigma detected: Use Short Name Path in Command Line
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: hAyQbTcI0I.exe Avira: detected
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Avira: detection malicious, Label: HEUR/AGEN.1314739
Source: C:\ProgramData\DP Free Video Converter 10.23.46\DP Free Video Converter 10.23.46.exe Avira: detection malicious, Label: HEUR/AGEN.1314739
Source: dpfreevideoconverter3264.exe.7644.3.memstrmin Malware Configuration Extractor: Socks5Systemz {"C2 list": ["csvskfe.net"]}
Source: C:\ProgramData\DP Free Video Converter 10.23.46\DP Free Video Converter 10.23.46.exe ReversingLabs: Detection: 34%
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe ReversingLabs: Detection: 34%
Source: hAyQbTcI0I.exe ReversingLabs: Detection: 23%
Source: hAyQbTcI0I.exe Virustotal: Detection: 12% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.9% probability
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Joe Sandbox ML: detected
Source: C:\ProgramData\DP Free Video Converter 10.23.46\DP Free Video Converter 10.23.46.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045A4FC GetProcAddress,GetProcAddress,GetProcAddress,ISCryptGetVersion, 2_2_0045A4FC
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045A5C8 ArcFourCrypt, 2_2_0045A5C8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045A5B0 ArcFourCrypt, 2_2_0045A5B0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_10001000 ISCryptGetVersion, 2_2_10001000
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_10001130 ArcFourCrypt, 2_2_10001130

Compliance

barindex
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Unpacked PE file: 3.2.dpfreevideoconverter3264.exe.400000.0.unpack
Source: hAyQbTcI0I.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047819C FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 2_2_0047819C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0046E788 FindFirstFileA,FindNextFileA,FindClose, 2_2_0046E788
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045105C FindFirstFileA,GetLastError, 2_2_0045105C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004760AC FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 2_2_004760AC
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045EB08 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 2_2_0045EB08
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045EF84 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 2_2_0045EF84
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0048F0A0 FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 2_2_0048F0A0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045D584 FindFirstFileA,FindNextFileA,FindClose, 2_2_0045D584
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData Jump to behavior

Networking

barindex
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49994 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50008 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49977 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49986 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49992 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49996 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50000 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49971 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49979 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50007 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49990 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49993 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49981 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50001 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49989 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49978 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49982 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50003 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49999 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49970 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49991 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49976 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50014 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49975 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50004 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50002 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50018 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49983 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49995 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50012 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50025 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49980 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49997 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49988 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50005 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49998 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49984 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50011 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50021 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49985 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50010 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50017 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50029 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50030 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50022 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50031 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50023 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50026 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50016 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50013 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50020 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50015 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50006 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50009 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50019 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:49987 -> 185.208.158.202:80
Source: Network traffic Suricata IDS: 2049467 - Severity 1 - ET MALWARE [ANY.RUN] Socks5Systemz HTTP C2 Connection M1 : 192.168.2.7:50024 -> 185.208.158.202:80
Source: Malware configuration extractor URLs: csvskfe.net
Source: global traffic TCP traffic: 192.168.2.7:49973 -> 89.105.201.183:2023
Source: Joe Sandbox View IP Address: 104.102.49.254 104.102.49.254
Source: Joe Sandbox View IP Address: 185.208.158.202 185.208.158.202
Source: Joe Sandbox View IP Address: 89.105.201.183 89.105.201.183
Source: Joe Sandbox View ASN Name: SIMPLECARRER2IT SIMPLECARRER2IT
Source: global traffic HTTP traffic detected: GET /inventory/76561199007797490/730/2?l=english&count=2000 HTTP/1.1Referer: https://steamcommunity.com/profiles/76561199007797490/inventory/X-Requested-With: XMLHttpRequestX-Prototype-Version: 1.7Accept: text/javascript, text/html, application/xml, text/xml, */*Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cache-Control: no-cacheDNT: 1Pragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36host: steamcommunity.comConnection: close
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c445db22f31dfe339426fa11af66c156adb719a9577e55b8603e983a608cf616c5ee9c9f3f HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c445db22f31dfe339426fa11af66c156adb719a9577e55b8603e983a608cf616c5ee9c9f3f HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown TCP traffic detected without corresponding DNS query: 89.105.201.183
Source: unknown UDP traffic detected without corresponding DNS query: 45.155.250.90
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CD72AB Sleep,RtlEnterCriticalSection,RtlLeaveCriticalSection,_memset,_memset,InternetOpenA,InternetSetOptionA,InternetSetOptionA,InternetSetOptionA,_memset,InternetOpenUrlA,InternetReadFile,InternetCloseHandle,InternetCloseHandle,_memset,RtlEnterCriticalSection,RtlLeaveCriticalSection,_malloc,RtlEnterCriticalSection,RtlLeaveCriticalSection,_memset,_memset,_memset,_memset,_memset,_malloc,_memset,_strtok,_swscanf,_strtok,_free,Sleep,_memset,RtlEnterCriticalSection,RtlLeaveCriticalSection,_sprintf,RtlEnterCriticalSection,RtlLeaveCriticalSection,_malloc,_memset,_free, 3_2_02CD72AB
Source: global traffic HTTP traffic detected: GET /inventory/76561199007797490/730/2?l=english&count=2000 HTTP/1.1Referer: https://steamcommunity.com/profiles/76561199007797490/inventory/X-Requested-With: XMLHttpRequestX-Prototype-Version: 1.7Accept: text/javascript, text/html, application/xml, text/xml, */*Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cache-Control: no-cacheDNT: 1Pragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36host: steamcommunity.comConnection: close
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c445db22f31dfe339426fa11af66c156adb719a9577e55b8603e983a608cf616c5ee9c9f3f HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c445db22f31dfe339426fa11af66c156adb719a9577e55b8603e983a608cf616c5ee9c9f3f HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic HTTP traffic detected: GET /search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978f4a885a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c9d3ecc669312 HTTP/1.1Host: csvskfe.netUser-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Source: global traffic DNS traffic detected: DNS query: csvskfe.net
Source: global traffic DNS traffic detected: DNS query: steamcommunity.com
Source: dpfreevideoconverter3264.exe, 00000003.00000002.2602262918.0000000003348000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.2
Source: dpfreevideoconverter3264.exe, 00000003.00000002.2602262918.0000000003348000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.208.158.202/sV
Source: dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A19000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2602262918.000000000331F000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2602262918.0000000003314000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A5B000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A41000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.208.158.202/search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12eab517aa5c96bd86e9978
Source: dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A54000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.208.158.202/search/?q=67e28dd86f09f429110aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82d
Source: hAyQbTcI0I.exe, 00000000.00000003.1337309119.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.exe, 00000000.00000002.2600194129.00000000022A8000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000002.2600536918.0000000002169000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1346454649.0000000000869000.00000004.00000020.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000002.2600180185.000000000084E000.00000004.00000020.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1340161721.000000000217C000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1340031274.0000000003110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://fsf.org/
Source: is-G27H3.tmp.2.dr String found in binary or memory: http://mingw-w64.sourceforge.net/X
Source: is-MLRBP.tmp.2.dr String found in binary or memory: http://tukaani.org/
Source: is-MLRBP.tmp.2.dr String found in binary or memory: http://tukaani.org/xz/
Source: hAyQbTcI0I.exe, 00000000.00000003.1337309119.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.exe, 00000000.00000002.2600194129.00000000022A8000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000002.2600536918.0000000002169000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1346454649.0000000000869000.00000004.00000020.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000002.2600180185.000000000084E000.00000004.00000020.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1340161721.000000000217C000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000003.1340031274.0000000003110000.00000004.00001000.00020000.00000000.sdmp, is-9LPV1.tmp.2.dr String found in binary or memory: http://www.gnu.org/licenses/
Source: hAyQbTcI0I.tmp, hAyQbTcI0I.tmp, 00000002.00000002.2599489013.0000000000401000.00000020.00000001.01000000.00000004.sdmp, hAyQbTcI0I.tmp.0.dr, is-6073S.tmp.2.dr String found in binary or memory: http://www.innosetup.com/
Source: hAyQbTcI0I.exe, 00000000.00000003.1337932678.00000000022B4000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.exe, 00000000.00000003.1337737042.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, hAyQbTcI0I.tmp, 00000002.00000002.2599489013.0000000000401000.00000020.00000001.01000000.00000004.sdmp, hAyQbTcI0I.tmp.0.dr, is-6073S.tmp.2.dr String found in binary or memory: http://www.remobjects.com/?ps
Source: hAyQbTcI0I.exe, 00000000.00000003.1337932678.00000000022B4000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.exe, 00000000.00000003.1337737042.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, hAyQbTcI0I.tmp, 00000002.00000002.2599489013.0000000000401000.00000020.00000001.01000000.00000004.sdmp, hAyQbTcI0I.tmp.0.dr, is-6073S.tmp.2.dr String found in binary or memory: http://www.remobjects.com/?psU
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50027
Source: unknown Network traffic detected: HTTP traffic on port 50027 -> 443
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0042ECCC NtdllDefWindowProc_A, 2_2_0042ECCC
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00423B1C NtdllDefWindowProc_A, 2_2_00423B1C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00412570 NtdllDefWindowProc_A, 2_2_00412570
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00455074 PostMessageA,PostMessageA,SetForegroundWindow,NtdllDefWindowProc_A, 2_2_00455074
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004718F0 NtdllDefWindowProc_A, 2_2_004718F0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0042E6BC: CreateFileA,DeviceIoControl,GetLastError,CloseHandle,SetLastError, 2_2_0042E6BC
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004092A0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004092A0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00453978 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 2_2_00453978
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004082E8 0_2_004082E8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004620A8 2_2_004620A8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0046A284 2_2_0046A284
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004349C0 2_2_004349C0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00478DF1 2_2_00478DF1
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004640C4 2_2_004640C4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00444100 2_2_00444100
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047E4E0 2_2_0047E4E0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00430564 2_2_00430564
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045876C 2_2_0045876C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004447F8 2_2_004447F8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00444C04 2_2_00444C04
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00484EC0 2_2_00484EC0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0043D3E0 2_2_0043D3E0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045B514 2_2_0045B514
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00443B58 2_2_00443B58
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0042FB08 2_2_0042FB08
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00433CBC 2_2_00433CBC
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_00406C47 3_2_00406C47
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_00401051 3_2_00401051
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_00401C26 3_2_00401C26
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CEE24D 3_2_02CEE24D
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CDF071 3_2_02CDF071
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CEE665 3_2_02CEE665
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CF5460 3_2_02CF5460
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CE8503 3_2_02CE8503
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CF4EE9 3_2_02CF4EE9
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CF2E74 3_2_02CF2E74
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CE9F44 3_2_02CE9F44
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CEACFA 3_2_02CEACFA
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CEDD59 3_2_02CEDD59
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02D0BF78 3_2_02D0BF78
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02D0BF29 3_2_02D0BF29
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02D0B4E5 3_2_02D0B4E5
Source: Joe Sandbox View Dropped File: C:\Users\user\AppData\Local\DP Free Video Converter\is-2N4MA.tmp 513CEC3CCBE4E0B31542C870793CCBDC79725718915DB0129AA39035202B7F97
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00405964 appears 100 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00445734 appears 58 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00403400 appears 59 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00406A1C appears 38 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00407884 appears 40 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00408B9C appears 44 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00445464 appears 44 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00433BD4 appears 32 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00403494 appears 83 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 004559F0 appears 65 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00451940 appears 70 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 00403684 appears 203 times
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: String function: 004557F0 appears 95 times
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: String function: 02CE8BA0 appears 37 times
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: String function: 02CF53F0 appears 138 times
Source: hAyQbTcI0I.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: hAyQbTcI0I.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) Intel Itanium, for MS Windows
Source: hAyQbTcI0I.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: hAyQbTcI0I.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-6073S.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-6073S.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) Intel Itanium, for MS Windows
Source: is-6073S.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: is-6073S.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-G27H3.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-4O0LJ.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-9LPV1.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-NED7E.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-L5N62.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-PPNQF.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-2N4MA.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-KGN1A.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-NOUEU.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-MLRBP.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-TFBPF.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: hAyQbTcI0I.exe, 00000000.00000003.1337932678.00000000022B4000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs hAyQbTcI0I.exe
Source: hAyQbTcI0I.exe, 00000000.00000003.1337932678.00000000022B4000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilename! vs hAyQbTcI0I.exe
Source: hAyQbTcI0I.exe, 00000000.00000003.1337737042.00000000024D0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs hAyQbTcI0I.exe
Source: hAyQbTcI0I.exe, 00000000.00000003.1337737042.00000000024D0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilename! vs hAyQbTcI0I.exe
Source: hAyQbTcI0I.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: _RegDLL.tmp.2.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: classification engine Classification label: mal100.troj.evad.winEXE@6/69@2/3
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CE08C0 _memset,FormatMessageA,GetLastError,FormatMessageA,GetLastError, 3_2_02CE08C0
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004092A0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004092A0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00453978 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 2_2_00453978
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004541A0 GetModuleHandleA,GetProcAddress,GetDiskFreeSpaceA, 2_2_004541A0
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: CloseServiceHandle,CreateServiceA, 3_2_0040288A
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00454624 CoCreateInstance,CoCreateInstance,SysFreeString, 2_2_00454624
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00409A00 FindResourceA,SizeofResource,LoadResource,LockResource, 0_2_00409A00
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_004025AA StartServiceCtrlDispatcherA, 3_2_004025AA
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_004025AA StartServiceCtrlDispatcherA, 3_2_004025AA
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter Jump to behavior
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe File created: C:\Users\user~1\AppData\Local\Temp\is-FR14S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: hAyQbTcI0I.exe ReversingLabs: Detection: 23%
Source: hAyQbTcI0I.exe Virustotal: Detection: 12%
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe File read: C:\Users\user\Desktop\hAyQbTcI0I.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\hAyQbTcI0I.exe "C:\Users\user\Desktop\hAyQbTcI0I.exe"
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Process created: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp "C:\Users\user~1\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp" /SL5="$1043E,4073274,53248,C:\Users\user\Desktop\hAyQbTcI0I.exe"
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process created: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe "C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe" -i
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Process created: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp "C:\Users\user~1\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp" /SL5="$1043E,4073274,53248,C:\Users\user\Desktop\hAyQbTcI0I.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process created: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe "C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe" -i Jump to behavior
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: licensemanagersvc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: licensemanager.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: clipc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Window found: window name: TMainForm Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: hAyQbTcI0I.exe Static file information: File size 4345372 > 1048576

Data Obfuscation

barindex
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Unpacked PE file: 3.2.dpfreevideoconverter3264.exe.400000.0.unpack .hreg4:EW;.ireg4:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.vmp0:ER;.rsrc:R;
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Unpacked PE file: 3.2.dpfreevideoconverter3264.exe.400000.0.unpack
Source: is-KSDHT.tmp.2.dr Static PE information: 0x8C00008C [Mon Jun 6 07:19:40 2044 UTC]
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00447B9C LoadLibraryExA,LoadLibraryA,GetProcAddress, 2_2_00447B9C
Source: initial sample Static PE information: section where entry point is pointing to: .hreg4
Source: dpfreevideoconverter3264.exe.2.dr Static PE information: section name: .hreg4
Source: dpfreevideoconverter3264.exe.2.dr Static PE information: section name: .ireg4
Source: is-37I6M.tmp.2.dr Static PE information: section name: /4
Source: is-4O0LJ.tmp.2.dr Static PE information: section name: /4
Source: is-TFBPF.tmp.2.dr Static PE information: section name: /4
Source: is-UUPB2.tmp.2.dr Static PE information: section name: /4
Source: is-RNIQ6.tmp.2.dr Static PE information: section name: /4
Source: is-ND6Q4.tmp.2.dr Static PE information: section name: /4
Source: is-9LPV1.tmp.2.dr Static PE information: section name: /4
Source: is-KSDHT.tmp.2.dr Static PE information: section name: /4
Source: is-E9QJH.tmp.2.dr Static PE information: section name: /4
Source: is-MLRBP.tmp.2.dr Static PE information: section name: /4
Source: is-QIJO8.tmp.2.dr Static PE information: section name: /4
Source: is-PPNQF.tmp.2.dr Static PE information: section name: /4
Source: is-KPCIR.tmp.2.dr Static PE information: section name: /4
Source: is-NOUEU.tmp.2.dr Static PE information: section name: /4
Source: is-2N4MA.tmp.2.dr Static PE information: section name: /4
Source: is-KGN1A.tmp.2.dr Static PE information: section name: /4
Source: is-NED7E.tmp.2.dr Static PE information: section name: /4
Source: is-LF8IA.tmp.2.dr Static PE information: section name: /4
Source: is-L5N62.tmp.2.dr Static PE information: section name: /4
Source: is-QM5QU.tmp.2.dr Static PE information: section name: /4
Source: is-L3IUL.tmp.2.dr Static PE information: section name: /4
Source: is-6HFPG.tmp.2.dr Static PE information: section name: /4
Source: is-7TG8V.tmp.2.dr Static PE information: section name: /4
Source: is-FBC4J.tmp.2.dr Static PE information: section name: /4
Source: is-2VULV.tmp.2.dr Static PE information: section name: /4
Source: is-G27H3.tmp.2.dr Static PE information: section name: /4
Source: is-S2ODS.tmp.2.dr Static PE information: section name: /4
Source: DP Free Video Converter 10.23.46.exe.3.dr Static PE information: section name: .hreg4
Source: DP Free Video Converter 10.23.46.exe.3.dr Static PE information: section name: .ireg4
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00406518 push 00406555h; ret 0_2_0040654D
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004040B5 push eax; ret 0_2_004040F1
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00404185 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00404206 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_0040C218 push eax; ret 0_2_0040C219
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004042E8 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00404283 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00408D90 push 00408DC3h; ret 0_2_00408DBB
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00407FE0 push ecx; mov dword ptr [esp], eax 0_2_00407FE5
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004098DC push 00409919h; ret 2_2_00409911
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004062BC push ecx; mov dword ptr [esp], eax 2_2_004062BD
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00430564 push ecx; mov dword ptr [esp], eax 2_2_00430569
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00410668 push ecx; mov dword ptr [esp], edx 2_2_0041066D
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004128C0 push 00412923h; ret 2_2_0041291B
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004508F8 push 0045092Bh; ret 2_2_00450923
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00442AD0 push ecx; mov dword ptr [esp], ecx 2_2_00442AD4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00470C04 push ecx; mov dword ptr [esp], edx 2_2_00470C05
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0040CFC0 push ecx; mov dword ptr [esp], edx 2_2_0040CFC2
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045725C push 004572A0h; ret 2_2_00457298
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045B20C push ecx; mov dword ptr [esp], eax 2_2_0045B211
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0040546D push eax; ret 2_2_004054A9
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047D4C0 push ecx; mov dword ptr [esp], ecx 2_2_0047D4C5
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0040F520 push ecx; mov dword ptr [esp], edx 2_2_0040F522
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0040553D push 00405749h; ret 2_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004055BE push 00405749h; ret 2_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0040563B push 00405749h; ret 2_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004056A0 push 00405749h; ret 2_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00455A8C push 00455AC4h; ret 2_2_00455ABC
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00419BC0 push ecx; mov dword ptr [esp], ecx 2_2_00419BC5
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047BE6C push 0047BF4Ah; ret 2_2_0047BF42
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00409FD7 push ds; ret 2_2_00409FD8

Persistence and Installation Behavior

barindex
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive0 3_2_00401A4F
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive0 3_2_02CDF89A
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-7TG8V.tmp Jump to dropped file
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe File created: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpng16-16.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_iscrypt.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgdk_pixbuf-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgdk-win32-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpangocairo-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-TFBPF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpangoft2-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgobject-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-L3IUL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgcc_s_dw2-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-9LPV1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpcre-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-2N4MA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libtiff-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libjpeg-8.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-PPNQF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-NOUEU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-2VULV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-KSDHT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-QIJO8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-S2ODS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-MLRBP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-RNIQ6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\uninstall\is-6073S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe File created: C:\ProgramData\DP Free Video Converter 10.23.46\DP Free Video Converter 10.23.46.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpixman-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\zlib1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\uninstall\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpango-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\librsvg-2-2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-QM5QU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-E9QJH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-FBC4J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-UUPB2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-6HFPG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libintl-8.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpangowin32-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libpangomm-1.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-G27H3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\liblcms2-2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\liblzma-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libglibmm-2.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgdkmm-2.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libsigc-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgraphite2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-ND6Q4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-KPCIR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libharfbuzz-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-37I6M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgmodule-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libgomp-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-4O0LJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-NED7E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-L5N62.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\libwinpthread-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-LF8IA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\DP Free Video Converter\is-KGN1A.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File created: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_RegDLL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe File created: C:\ProgramData\DP Free Video Converter 10.23.46\DP Free Video Converter 10.23.46.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive0 3_2_00401A4F
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive0 3_2_02CDF89A
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_004025AA StartServiceCtrlDispatcherA, 3_2_004025AA
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00423BA4 IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 2_2_00423BA4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00423BA4 IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 2_2_00423BA4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00424174 IsIconic,SetActiveWindow,SetFocus, 2_2_00424174
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0042412C IsIconic,SetActiveWindow, 2_2_0042412C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0041831C IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, 2_2_0041831C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004227F4 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, 2_2_004227F4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00417530 IsIconic,GetCapture, 2_2_00417530
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047B83C IsIconic,GetWindowLongA,ShowWindow,ShowWindow, 2_2_0047B83C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00417C66 IsIconic,SetWindowPos, 2_2_00417C66
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00417C68 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, 2_2_00417C68
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0044A9DC LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 2_2_0044A9DC
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: LoadLibraryA,GetProcAddress,GetAdaptersInfo,FreeLibrary, 3_2_00401B4B
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: LoadLibraryA,GetProcAddress,GetAdaptersInfo,FreeLibrary, 3_2_02CDF99E
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Window / User API: threadDelayed 3479 Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Window / User API: threadDelayed 6397 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-7TG8V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpng16-16.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_iscrypt.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgdk_pixbuf-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpangocairo-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgdk-win32-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpangoft2-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-TFBPF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-L3IUL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgobject-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgcc_s_dw2-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-9LPV1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpcre-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-2N4MA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libtiff-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libjpeg-8.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-PPNQF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-2VULV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-NOUEU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-KSDHT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-QIJO8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-S2ODS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-MLRBP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-RNIQ6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\uninstall\is-6073S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpixman-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\zlib1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpango-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\uninstall\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\librsvg-2-2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-QM5QU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-E9QJH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-FBC4J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-UUPB2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-6HFPG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libintl-8.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpangowin32-1.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libpangomm-1.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-G27H3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\liblzma-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\liblcms2-2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libglibmm-2.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgdkmm-2.4-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libsigc-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgraphite2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-ND6Q4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-KPCIR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libharfbuzz-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-37I6M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgmodule-2.0-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libgomp-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-4O0LJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-NED7E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-L5N62.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\libwinpthread-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-LF8IA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\DP Free Video Converter\is-KGN1A.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-DSMCE.tmp\_isetup\_RegDLL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Evasive API call chain: GetSystemTime,DecisionNodes
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Evasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 7648 Thread sleep count: 3479 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 7648 Thread sleep time: -6958000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 8008 Thread sleep count: 56 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 8008 Thread sleep time: -3360000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 7648 Thread sleep count: 6397 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe TID: 7648 Thread sleep time: -12794000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe File opened: PhysicalDrive0 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047819C FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 2_2_0047819C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0046E788 FindFirstFileA,FindNextFileA,FindClose, 2_2_0046E788
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045105C FindFirstFileA,GetLastError, 2_2_0045105C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_004760AC FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 2_2_004760AC
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045EB08 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 2_2_0045EB08
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045EF84 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 2_2_0045EF84
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0048F0A0 FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 2_2_0048F0A0
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0045D584 FindFirstFileA,FindNextFileA,FindClose, 2_2_0045D584
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00409944 GetSystemInfo,VirtualQuery,VirtualProtect,VirtualProtect,VirtualQuery, 0_2_00409944
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Thread delayed: delay time: 60000 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp File opened: C:\Users\user\AppData Jump to behavior
Source: dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A5B000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000A41000.00000004.00000020.00020000.00000000.sdmp, dpfreevideoconverter3264.exe, 00000003.00000002.2600247342.0000000000968000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CF01BE RtlEncodePointer,RtlEncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,IsDebuggerPresent,OutputDebugStringW,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer, 3_2_02CF01BE
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CF01BE RtlEncodePointer,RtlEncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,IsDebuggerPresent,OutputDebugStringW,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer, 3_2_02CF01BE
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00447B9C LoadLibraryExA,LoadLibraryA,GetProcAddress, 2_2_00447B9C
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CD648B RtlInitializeCriticalSection,GetModuleHandleA,GetModuleHandleA,GetProcAddress,GetProcAddress,GetModuleHandleA,GetProcAddress,GetTickCount,GetVersionExA,_memset,_malloc,_malloc,_malloc,_malloc,_malloc,_malloc,_malloc,_malloc,GetProcessHeap,GetProcessHeap,RtlAllocateHeap,RtlAllocateHeap,GetProcessHeap,RtlAllocateHeap,GetProcessHeap,RtlAllocateHeap,_memset,_memset,_memset,RtlEnterCriticalSection,RtlLeaveCriticalSection,_malloc,_malloc,_malloc,_malloc,QueryPerformanceCounter,Sleep,_malloc,_malloc,_memset,_memset,Sleep,RtlEnterCriticalSection,RtlLeaveCriticalSection,_memset,_memset, 3_2_02CD648B
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CE9528 SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_02CE9528
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0047138C ShellExecuteEx,GetLastError,MsgWaitForMultipleObjects,GetExitCodeProcess,CloseHandle, 2_2_0047138C
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_0042DE9C AllocateAndInitializeSid,GetVersion,GetModuleHandleA,GetProcAddress,GetCurrentThread,OpenThreadToken,GetLastError,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,FreeSid, 2_2_0042DE9C
Source: C:\Users\user\AppData\Local\DP Free Video Converter\dpfreevideoconverter3264.exe Code function: 3_2_02CE806E cpuid 3_2_02CE806E
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: GetLocaleInfoA, 0_2_0040515C
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: GetLocaleInfoA, 0_2_004051A8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: GetLocaleInfoA, 2_2_004084F8
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: GetLocaleInfoA, 2_2_00408544
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00456538 GetTickCount,QueryPerformanceCounter,GetSystemTimeAsFileTime,GetCurrentProcessId,CreateNamedPipeA,GetLastError,CreateFileA,SetNamedPipeHandleState,CreateProcessA,CloseHandle,CloseHandle, 2_2_00456538
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_004026C4 GetSystemTime, 0_2_004026C4
Source: C:\Users\user\AppData\Local\Temp\is-FR14S.tmp\hAyQbTcI0I.tmp Code function: 2_2_00453930 GetUserNameA, 2_2_00453930
Source: C:\Users\user\Desktop\hAyQbTcI0I.exe Code function: 0_2_00405C44 GetVersionExA, 0_2_00405C44

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000003.00000002.2601842045.0000000002CD1000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.2601753399.0000000002C27000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: dpfreevideoconverter3264.exe PID: 7644, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: 00000003.00000002.2601842045.0000000002CD1000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.2601753399.0000000002C27000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: dpfreevideoconverter3264.exe PID: 7644, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs