Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
0_2_00408349 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
1_2_00408349 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
2_2_00408349 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
3_2_00408349 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
4_2_00408349 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
5_2_00408349 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
6_2_00408349 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
8_2_00408349 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
9_2_00408349 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
10_2_00408349 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
11_2_00408349 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
12_2_00408349 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
13_2_00408349 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
14_2_00408349 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
15_2_00408349 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
16_2_00408349 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
17_2_00408349 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
18_2_00408349 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
19_2_00408349 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
20_2_00408349 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
21_2_00408349 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
22_2_00408349 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
23_2_00408349 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
24_2_00408349 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
25_2_00408349 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
26_2_00408349 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then push 00000004h |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then push eax |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov eax, ecx |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then pop eax |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov esi, 3EC93B07h |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xchg eax, ecx |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov esi, 0255568Dh |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add eax, edi |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then popad |
0_2_00432003 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then je 004071F6h |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then inc eax |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then jne 004071CCh |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov eax, 0042C000h |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then je 0040722Ch |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add eax, 04h |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then jne 00407214h |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then popad |
0_2_004071A8 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
0_2_00407245 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add ebx, 04h |
0_2_00407245 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then jl 00407269h |
0_2_00407245 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add eax, 0Ch |
0_2_00407245 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then popad |
0_2_00407245 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then pop edi |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then sub ecx, eax |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xor edx, edx |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then push eax |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then div edi |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xchg eax, ecx |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add eax, edi |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then loop 00407318h |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov eax, 0042C000h |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then mov ebx, 0042F314h |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then sub ecx, eax |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xor edx, edx |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then push eax |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then div edi |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then xchg eax, ecx |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then add eax, edi |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then loop 00407378h |
0_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 4x nop then popad |
0_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then inc eax |
1_2_00432003 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xchg eax, ecx |
1_2_0043209D |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov esi, 0255568Dh |
1_2_0043209D |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add eax, edi |
1_2_0043209D |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then popad |
1_2_0043209D |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then je 004071F6h |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then inc eax |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then jne 004071CCh |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov eax, 0042C000h |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then je 0040722Ch |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add eax, 04h |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then jne 00407214h |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then popad |
1_2_004071A8 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
1_2_00407245 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add ebx, 04h |
1_2_00407245 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then jl 00407269h |
1_2_00407245 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add eax, 0Ch |
1_2_00407245 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then popad |
1_2_00407245 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then pop edi |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then sub ecx, eax |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xor edx, edx |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then push eax |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then div edi |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xchg eax, ecx |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add eax, edi |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then loop 00407318h |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov eax, 0042C000h |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then mov ebx, 0042F314h |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then sub ecx, eax |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xor edx, edx |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then push eax |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then div edi |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then xchg eax, ecx |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then add eax, edi |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then loop 00407378h |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 4x nop then popad |
1_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov eax, 00401000h |
2_2_00432003 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then jne 00432024h |
2_2_00432017 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then jmp 00401219h |
2_2_00432017 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xchg eax, ecx |
2_2_0043209D |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov esi, 0255568Dh |
2_2_0043209D |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add eax, edi |
2_2_0043209D |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then popad |
2_2_0043209D |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then je 004071F6h |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then inc eax |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then jne 004071CCh |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov eax, 0042C000h |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then je 0040722Ch |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add eax, 04h |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then jne 00407214h |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then popad |
2_2_004071A8 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
2_2_00407245 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add ebx, 04h |
2_2_00407245 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then jl 00407269h |
2_2_00407245 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add eax, 0Ch |
2_2_00407245 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then popad |
2_2_00407245 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then pop edi |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then sub ecx, eax |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xor edx, edx |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then push eax |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then div edi |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xchg eax, ecx |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add eax, edi |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then loop 00407318h |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov eax, 0042C000h |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then mov ebx, 0042F314h |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then sub ecx, eax |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xor edx, edx |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then push eax |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then div edi |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then xchg eax, ecx |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then add eax, edi |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then loop 00407378h |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 4x nop then popad |
2_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, 0040729Fh |
3_2_0043200C |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then cmp dword ptr [eax], 00000000h |
3_2_0043200C |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xchg eax, ecx |
3_2_0043209D |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov esi, 0255568Dh |
3_2_0043209D |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, edi |
3_2_0043209D |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then popad |
3_2_0043209D |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then je 004071F6h |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then inc eax |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then jne 004071CCh |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov eax, 0042C000h |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then je 0040722Ch |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, 04h |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then jne 00407214h |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then popad |
3_2_004071A8 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
3_2_00407245 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add ebx, 04h |
3_2_00407245 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then jl 00407269h |
3_2_00407245 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, 0Ch |
3_2_00407245 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then popad |
3_2_00407245 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then pop edi |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then sub ecx, eax |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xor edx, edx |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then push eax |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then div edi |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xchg eax, ecx |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, edi |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then loop 00407318h |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov eax, 0042C000h |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then mov ebx, 0042F314h |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then sub ecx, eax |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xor edx, edx |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then push eax |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then div edi |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then xchg eax, ecx |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then add eax, edi |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then loop 00407378h |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 4x nop then popad |
3_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then je 0043204Eh |
4_2_00432003 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then inc eax |
4_2_00432003 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then jne 00432024h |
4_2_00432003 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xchg eax, ecx |
4_2_0043209D |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov esi, 0255568Dh |
4_2_0043209D |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add eax, edi |
4_2_0043209D |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then popad |
4_2_0043209D |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then je 004071F6h |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then inc eax |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then jne 004071CCh |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov eax, 0042C000h |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then je 0040722Ch |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add eax, 04h |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then jne 00407214h |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then popad |
4_2_004071A8 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
4_2_00407245 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add ebx, 04h |
4_2_00407245 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then jl 00407269h |
4_2_00407245 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add eax, 0Ch |
4_2_00407245 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then popad |
4_2_00407245 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then pop edi |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then sub ecx, eax |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xor edx, edx |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then push eax |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then div edi |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xchg eax, ecx |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add eax, edi |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then loop 00407318h |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov eax, 0042C000h |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then mov ebx, 0042F314h |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then sub ecx, eax |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xor edx, edx |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then push eax |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then div edi |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then xchg eax, ecx |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then add eax, edi |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then loop 00407378h |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4x nop then popad |
4_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov eax, 00401000h |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then je 00432072h |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then je 004320D2h |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then pop eax |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov esi, 68F61C4Ch |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then jmp 00401219h |
5_2_00432003 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then je 004071F6h |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then inc eax |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then jne 004071CCh |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov eax, 0042C000h |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then je 0040722Ch |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then add eax, 04h |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then jne 00407214h |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then popad |
5_2_004071A8 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
5_2_00407245 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then add ebx, 04h |
5_2_00407245 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then jl 00407269h |
5_2_00407245 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then add eax, 0Ch |
5_2_00407245 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then popad |
5_2_00407245 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then pop edi |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then sub ecx, eax |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xor edx, edx |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then push eax |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then div edi |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xchg eax, ecx |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then add eax, edi |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then loop 00407318h |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov eax, 0042C000h |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then mov ebx, 0042F314h |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then sub ecx, eax |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xor edx, edx |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then push eax |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then div edi |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then xchg eax, ecx |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then add eax, edi |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then loop 00407378h |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 4x nop then popad |
5_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then pop eax |
6_2_00432068 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov esi, 68F61C4Ch |
6_2_00432068 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then jmp 00401219h |
6_2_00432068 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then je 004071F6h |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then inc eax |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then jne 004071CCh |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov eax, 0042C000h |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then je 0040722Ch |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then add eax, 04h |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then jne 00407214h |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then popad |
6_2_004071A8 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
6_2_00407245 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then add ebx, 04h |
6_2_00407245 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then jl 00407269h |
6_2_00407245 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then add eax, 0Ch |
6_2_00407245 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then popad |
6_2_00407245 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then pop edi |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then sub ecx, eax |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xor edx, edx |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then push eax |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then div edi |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xchg eax, ecx |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then add eax, edi |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then loop 00407318h |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov eax, 0042C000h |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then mov ebx, 0042F314h |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then sub ecx, eax |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xor edx, edx |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then push eax |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then div edi |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then xchg eax, ecx |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then add eax, edi |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then loop 00407378h |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 4x nop then popad |
6_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then je 0043204Eh |
8_2_00432003 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
8_2_00432003 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then jne 00432024h |
8_2_00432003 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then pop eax |
8_2_0043209D |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov esi, 68F61C4Ch |
8_2_0043209D |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then jmp 00401219h |
8_2_0043209D |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then je 004071F6h |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then inc eax |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then jne 004071CCh |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov eax, 0042C000h |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then je 0040722Ch |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then add eax, 04h |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then jne 00407214h |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then popad |
8_2_004071A8 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
8_2_00407245 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then add ebx, 04h |
8_2_00407245 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then jl 00407269h |
8_2_00407245 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then add eax, 0Ch |
8_2_00407245 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then popad |
8_2_00407245 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then pop edi |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then sub ecx, eax |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xor edx, edx |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then push eax |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then div edi |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xchg eax, ecx |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then add eax, edi |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then loop 00407318h |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov eax, 0042C000h |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then mov ebx, 0042F314h |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then sub ecx, eax |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xor edx, edx |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then push eax |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then div edi |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then xchg eax, ecx |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then add eax, edi |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then loop 00407378h |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 4x nop then popad |
8_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then cmp eax, 00000000h |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov ecx, ebx |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor edx, edx |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov eax, ecx |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then pop eax |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor dword ptr [eax], esi |
9_2_00432003 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then je 004071F6h |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then inc eax |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then jne 004071CCh |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov eax, 0042C000h |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then je 0040722Ch |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then add eax, 04h |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then jne 00407214h |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then popad |
9_2_004071A8 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
9_2_00407245 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then add ebx, 04h |
9_2_00407245 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then jl 00407269h |
9_2_00407245 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then add eax, 0Ch |
9_2_00407245 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then popad |
9_2_00407245 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then pop edi |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then sub ecx, eax |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor edx, edx |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then push eax |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then div edi |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xchg eax, ecx |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then add eax, edi |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then loop 00407318h |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov eax, 0042C000h |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then mov ebx, 0042F314h |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then sub ecx, eax |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xor edx, edx |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then push eax |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then div edi |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then xchg eax, ecx |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then add eax, edi |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then loop 00407378h |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 4x nop then popad |
9_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then je 004071F6h |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then inc eax |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then jne 004071CCh |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then mov eax, 0042C000h |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then je 0040722Ch |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then add eax, 04h |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then jne 00407214h |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then popad |
10_2_004071A8 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
10_2_00407245 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then add ebx, 04h |
10_2_00407245 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then jl 00407269h |
10_2_00407245 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then add eax, 0Ch |
10_2_00407245 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then popad |
10_2_00407245 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then pop edi |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then sub ecx, eax |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xor edx, edx |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then push eax |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then div edi |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xchg eax, ecx |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then add eax, edi |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then loop 00407318h |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then mov eax, 0042C000h |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then mov ebx, 0042F314h |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then sub ecx, eax |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xor edx, edx |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then push eax |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then div edi |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then xchg eax, ecx |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then add eax, edi |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then loop 00407378h |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 4x nop then popad |
10_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
11_2_00432003 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then test eax, eax |
11_2_00432003 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add eax, 04h |
11_2_00432003 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor dword ptr [eax], esi |
11_2_0043209F |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then je 004071F6h |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then inc eax |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then jne 004071CCh |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then mov eax, 0042C000h |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then je 0040722Ch |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add eax, 04h |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then jne 00407214h |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then popad |
11_2_004071A8 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
11_2_00407245 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add ebx, 04h |
11_2_00407245 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then jl 00407269h |
11_2_00407245 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add eax, 0Ch |
11_2_00407245 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then popad |
11_2_00407245 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then pop edi |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then sub ecx, eax |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor edx, edx |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then push eax |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then div edi |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xchg eax, ecx |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add eax, edi |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then loop 00407318h |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then mov eax, 0042C000h |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then mov ebx, 0042F314h |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then sub ecx, eax |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xor edx, edx |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then push eax |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then div edi |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then xchg eax, ecx |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then add eax, edi |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then loop 00407378h |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 4x nop then popad |
11_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then pop edi |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then sub ecx, eax |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then div edi |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov esi, 76D87171h |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov ebx, 0042F314h |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xor edx, edx |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then push eax |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then loop 004320C0h |
12_2_00432003 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then je 004071F6h |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then inc eax |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then jne 004071CCh |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov eax, 0042C000h |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then je 0040722Ch |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then add eax, 04h |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then jne 00407214h |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then popad |
12_2_004071A8 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
12_2_00407245 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then add ebx, 04h |
12_2_00407245 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then jl 00407269h |
12_2_00407245 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then add eax, 0Ch |
12_2_00407245 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then popad |
12_2_00407245 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then pop edi |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then sub ecx, eax |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xor edx, edx |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then push eax |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then div edi |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xchg eax, ecx |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then add eax, edi |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then loop 00407318h |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov eax, 0042C000h |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then mov ebx, 0042F314h |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then sub ecx, eax |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xor edx, edx |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then push eax |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then div edi |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then xchg eax, ecx |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then add eax, edi |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then loop 00407378h |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 4x nop then popad |
12_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then test eax, eax |
13_2_00432003 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then loop 004320C0h |
13_2_0043209D |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then je 004071F6h |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then inc eax |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then jne 004071CCh |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then mov eax, 0042C000h |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then je 0040722Ch |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then xor dword ptr [eax], ecx |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then add eax, 04h |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then jne 00407214h |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then popad |
13_2_004071A8 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then mov ecx, dword ptr [eax+04h] |
13_2_00407245 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then add ebx, 04h |
13_2_00407245 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then jl 00407269h |
13_2_00407245 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then add eax, 0Ch |
13_2_00407245 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then popad |
13_2_00407245 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then pop edi |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then mov ebx, 0040C7D0h |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then sub ecx, eax |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then xor edx, edx |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then push eax |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then div edi |
13_2_004072A1 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 4x nop then xchg eax, ecx |
13_2_004072A1 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Section loaded: crtdll.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\Dkmigjhi.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dkmigjhi.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dkmigjhi.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dkmigjhi.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dkmigjhi.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dfbmdbho.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dfbmdbho.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dfbmdbho.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dfbmdbho.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dfbmdbho.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dokbmhoo.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dokbmhoo.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dokbmhoo.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dokbmhoo.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dokbmhoo.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dkbbbi32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dkbbbi32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dkbbbi32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dkbbbi32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dkbbbi32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dfggpb32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dfggpb32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dfggpb32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dfggpb32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dfggpb32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dkdohi32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dkdohi32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dkdohi32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dkdohi32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dkdohi32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Djepfp32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Djepfp32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Djepfp32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Djepfp32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Djepfp32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Dobhng32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Dobhng32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Dobhng32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Dobhng32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Dobhng32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Ejhlkp32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Ejhlkp32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Ejhlkp32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Ejhlkp32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Ejhlkp32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Ebcapbfh.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Ebcapbfh.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Ebcapbfh.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Ebcapbfh.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Ebcapbfh.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Epgaifdb.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Epgaifdb.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Epgaifdb.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Epgaifdb.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Epgaifdb.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Elnbng32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Elnbng32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Elnbng32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Elnbng32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Elnbng32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\Ejoblo32.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\Ejoblo32.exe |
Section loaded: wsock32.dll |
|
Source: C:\Windows\SysWOW64\Ejoblo32.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\SysWOW64\Ejoblo32.exe |
Section loaded: crtdll.dll |
|
Source: C:\Windows\SysWOW64\Ejoblo32.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
0_2_00408349 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
1_2_00408349 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
2_2_00408349 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
3_2_00408349 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
4_2_00408349 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
5_2_00408349 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
6_2_00408349 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
8_2_00408349 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
9_2_00408349 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
10_2_00408349 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
11_2_00408349 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
12_2_00408349 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
13_2_00408349 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
14_2_00408349 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
15_2_00408349 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
16_2_00408349 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
17_2_00408349 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
18_2_00408349 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
19_2_00408349 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
20_2_00408349 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
21_2_00408349 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
22_2_00408349 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
23_2_00408349 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
24_2_00408349 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
25_2_00408349 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_00408349 lstrlenA,send,sprintf,sprintf,lstrlenA,send,FindFirstFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindNextFileA,FileTimeToSystemTime,sprintf,lstrlenA,send,FindClose,closesocket,lstrlenA,send, |
26_2_00408349 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
0_2_0040A029 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
0_2_0040A737 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
1_2_0040A029 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
1_2_0040A737 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
2_2_0040A029 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
2_2_0040A737 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
3_2_0040A029 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
3_2_0040A737 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
4_2_0040A029 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
4_2_0040A737 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
5_2_0040A029 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
5_2_0040A737 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
6_2_0040A029 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
6_2_0040A737 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
8_2_0040A029 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
8_2_0040A737 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
9_2_0040A029 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
9_2_0040A737 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
10_2_0040A029 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
10_2_0040A737 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
11_2_0040A029 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
11_2_0040A737 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
12_2_0040A029 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
12_2_0040A737 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
13_2_0040A029 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
13_2_0040A737 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
14_2_0040A029 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
14_2_0040A737 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
15_2_0040A029 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
15_2_0040A737 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
16_2_0040A029 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
16_2_0040A737 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
17_2_0040A029 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
17_2_0040A737 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
18_2_0040A029 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
18_2_0040A737 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
19_2_0040A029 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
19_2_0040A737 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
20_2_0040A029 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
20_2_0040A737 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
21_2_0040A029 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
21_2_0040A737 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
22_2_0040A029 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
22_2_0040A737 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
23_2_0040A029 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
23_2_0040A737 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
24_2_0040A029 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
24_2_0040A737 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
25_2_0040A029 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
25_2_0040A737 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_0040A029 lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,InterlockedIncrement,memset,GetTickCount,srand,LocalFree,ExpandEnvironmentStringsA,LocalFree,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,Sleep,GetWindowTextA,DeleteFileA,LocalFree,TerminateProcess,CloseHandle, |
26_2_0040A029 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_0040A737 lstrlenA,GetTickCount,srand,InterlockedIncrement,memset,ExpandEnvironmentStringsA,strcat,strcat,memset,CreateProcessA,CloseHandle,sprintf,FindWindowA,Sleep,Sleep,GetWindowTextA,CopyFileA,DeleteFileA,lstrlenA,strncmp,lstrlenA,LocalFree,DeleteFileA,TerminateProcess,CloseHandle, |
26_2_0040A737 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
0_2_0040947E |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
0_2_0040400C |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
0_2_00405536 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
0_2_004079F2 |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_00403DAB htons,bind,listen,accept,htons, |
0_2_00403DAB |
Source: C:\Users\user\Desktop\puTBVYGxNA.exe |
Code function: 0_2_00403E36 listen, |
0_2_00403E36 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
1_2_0040947E |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
1_2_0040400C |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
1_2_00405536 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
1_2_004079F2 |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_00403DAB htons,bind,listen,accept,htons, |
1_2_00403DAB |
Source: C:\Windows\SysWOW64\Pojgioig.exe |
Code function: 1_2_00403E36 listen, |
1_2_00403E36 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
2_2_0040947E |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
2_2_0040400C |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
2_2_00405536 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
2_2_004079F2 |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_00403DAB htons,bind,listen,accept,htons, |
2_2_00403DAB |
Source: C:\Windows\SysWOW64\Piokfhim.exe |
Code function: 2_2_00403E36 listen, |
2_2_00403E36 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
3_2_0040947E |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
3_2_0040400C |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
3_2_00405536 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
3_2_004079F2 |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_00403DAB htons,bind,listen,accept,htons, |
3_2_00403DAB |
Source: C:\Windows\SysWOW64\Peflki32.exe |
Code function: 3_2_00403E36 listen, |
3_2_00403E36 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
4_2_0040947E |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
4_2_0040400C |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
4_2_00405536 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
4_2_004079F2 |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_00403DAB htons,bind,listen,accept,htons, |
4_2_00403DAB |
Source: C:\Windows\SysWOW64\Pbjldmnk.exe |
Code function: 4_2_00403E36 listen, |
4_2_00403E36 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
5_2_0040947E |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
5_2_0040400C |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
5_2_00405536 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
5_2_004079F2 |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_00403DAB htons,bind,listen,accept,htons, |
5_2_00403DAB |
Source: C:\Windows\SysWOW64\Phgemdlb.exe |
Code function: 5_2_00403E36 listen, |
5_2_00403E36 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
6_2_0040947E |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
6_2_0040400C |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
6_2_00405536 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
6_2_004079F2 |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_00403DAB htons,bind,listen,accept,htons, |
6_2_00403DAB |
Source: C:\Windows\SysWOW64\Qclijmlh.exe |
Code function: 6_2_00403E36 listen, |
6_2_00403E36 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
8_2_0040947E |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
8_2_0040400C |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
8_2_00405536 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
8_2_004079F2 |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_00403DAB htons,bind,listen,accept,htons, |
8_2_00403DAB |
Source: C:\Windows\SysWOW64\Qlencbbi.exe |
Code function: 8_2_00403E36 listen, |
8_2_00403E36 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
9_2_0040947E |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
9_2_0040400C |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
9_2_00405536 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
9_2_004079F2 |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_00403DAB htons,bind,listen,accept,htons, |
9_2_00403DAB |
Source: C:\Windows\SysWOW64\Qiinlgab.exe |
Code function: 9_2_00403E36 listen, |
9_2_00403E36 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
10_2_0040947E |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
10_2_0040400C |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
10_2_00405536 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
10_2_004079F2 |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_00403DAB htons,bind,listen,accept,htons, |
10_2_00403DAB |
Source: C:\Windows\SysWOW64\Acabel32.exe |
Code function: 10_2_00403E36 listen, |
10_2_00403E36 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
11_2_0040947E |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
11_2_0040400C |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
11_2_00405536 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
11_2_004079F2 |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_00403DAB htons,bind,listen,accept,htons, |
11_2_00403DAB |
Source: C:\Windows\SysWOW64\Ahnkmc32.exe |
Code function: 11_2_00403E36 listen, |
11_2_00403E36 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
12_2_0040947E |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
12_2_0040400C |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
12_2_00405536 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
12_2_004079F2 |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_00403DAB htons,bind,listen,accept,htons, |
12_2_00403DAB |
Source: C:\Windows\SysWOW64\Aafpfi32.exe |
Code function: 12_2_00403E36 listen, |
12_2_00403E36 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
13_2_0040947E |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
13_2_0040400C |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
13_2_00405536 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
13_2_004079F2 |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_00403DAB htons,bind,listen,accept,htons, |
13_2_00403DAB |
Source: C:\Windows\SysWOW64\Acflplcn.exe |
Code function: 13_2_00403E36 listen, |
13_2_00403E36 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
14_2_0040947E |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
14_2_0040400C |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
14_2_00405536 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
14_2_004079F2 |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_00403DAB htons,bind,listen,accept,htons, |
14_2_00403DAB |
Source: C:\Windows\SysWOW64\Ahbdhbbe.exe |
Code function: 14_2_00403E36 listen, |
14_2_00403E36 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
15_2_0040947E |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
15_2_0040400C |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
15_2_00405536 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
15_2_004079F2 |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_00403DAB htons,bind,listen,accept,htons, |
15_2_00403DAB |
Source: C:\Windows\SysWOW64\Aakiahhf.exe |
Code function: 15_2_00403E36 listen, |
15_2_00403E36 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
16_2_0040947E |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
16_2_0040400C |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
16_2_00405536 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
16_2_004079F2 |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_00403DAB htons,bind,listen,accept,htons, |
16_2_00403DAB |
Source: C:\Windows\SysWOW64\Aheanb32.exe |
Code function: 16_2_00403E36 listen, |
16_2_00403E36 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
17_2_0040947E |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
17_2_0040400C |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
17_2_00405536 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
17_2_004079F2 |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_00403DAB htons,bind,listen,accept,htons, |
17_2_00403DAB |
Source: C:\Windows\SysWOW64\Acjekk32.exe |
Code function: 17_2_00403E36 listen, |
17_2_00403E36 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
18_2_0040947E |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
18_2_0040400C |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
18_2_00405536 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
18_2_004079F2 |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_00403DAB htons,bind,listen,accept,htons, |
18_2_00403DAB |
Source: C:\Windows\SysWOW64\Bkfjpm32.exe |
Code function: 18_2_00403E36 listen, |
18_2_00403E36 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
19_2_0040947E |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
19_2_0040400C |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
19_2_00405536 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
19_2_004079F2 |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_00403DAB htons,bind,listen,accept,htons, |
19_2_00403DAB |
Source: C:\Windows\SysWOW64\Bapbmg32.exe |
Code function: 19_2_00403E36 listen, |
19_2_00403E36 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
20_2_0040947E |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
20_2_0040400C |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
20_2_00405536 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
20_2_004079F2 |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_00403DAB htons,bind,listen,accept,htons, |
20_2_00403DAB |
Source: C:\Windows\SysWOW64\Blefjp32.exe |
Code function: 20_2_00403E36 listen, |
20_2_00403E36 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
21_2_0040947E |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
21_2_0040400C |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
21_2_00405536 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
21_2_004079F2 |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_00403DAB htons,bind,listen,accept,htons, |
21_2_00403DAB |
Source: C:\Windows\SysWOW64\Bcoofjkc.exe |
Code function: 21_2_00403E36 listen, |
21_2_00403E36 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
22_2_0040947E |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
22_2_0040400C |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
22_2_00405536 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
22_2_004079F2 |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_00403DAB htons,bind,listen,accept,htons, |
22_2_00403DAB |
Source: C:\Windows\SysWOW64\Bcfegi32.exe |
Code function: 22_2_00403E36 listen, |
22_2_00403E36 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
23_2_0040947E |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
23_2_0040400C |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
23_2_00405536 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
23_2_004079F2 |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_00403DAB htons,bind,listen,accept,htons, |
23_2_00403DAB |
Source: C:\Windows\SysWOW64\Chhgjp32.exe |
Code function: 23_2_00403E36 listen, |
23_2_00403E36 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
24_2_0040947E |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
24_2_0040400C |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
24_2_00405536 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
24_2_004079F2 |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_00403DAB htons,bind,listen,accept,htons, |
24_2_00403DAB |
Source: C:\Windows\SysWOW64\Cjjpjb32.exe |
Code function: 24_2_00403E36 listen, |
24_2_00403E36 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
25_2_0040947E |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
25_2_0040400C |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
25_2_00405536 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
25_2_004079F2 |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_00403DAB htons,bind,listen,accept,htons, |
25_2_00403DAB |
Source: C:\Windows\SysWOW64\Ckklbjkl.exe |
Code function: 25_2_00403E36 listen, |
25_2_00403E36 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_0040947E memset,socket,htons,bind,closesocket,listen,accept,closesocket,CreateThread,CloseHandle, |
26_2_0040947E |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_0040400C socket,htonl,htons,bind,listen,accept,CreateThread,CloseHandle, |
26_2_0040400C |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_00405536 socket,htons,bind,listen,accept,closesocket,CreateThread,CloseHandle, |
26_2_00405536 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_004079F2 memset,socket,htons,bind,listen,memset,accept,CreateThread,CloseHandle,sprintf,closesocket,memset, |
26_2_004079F2 |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_00403DAB htons,bind,listen,accept,htons, |
26_2_00403DAB |
Source: C:\Windows\SysWOW64\Cfpqocja.exe |
Code function: 26_2_00403E36 listen, |
26_2_00403E36 |