Windows Analysis Report
WirelessMedia.exe

Overview

General Information

Sample name: WirelessMedia.exe
Analysis ID: 1544380
MD5: 014a54772378c797b10fc7f764aeb070
SHA1: 30892aa18b807e9fb9de4629f9c00a495f7152e7
SHA256: fa24b05dae7d2d915e3a71106509df6fe3892b35337fcb81e6bb1d99bb0b5dfe
Infos:

Detection

Score: 5
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Compliance

Score: 47
Range: 0 - 100

Signatures

Abnormal high CPU Usage
Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Installs a raw input device (often for capturing keystrokes)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sleep loop found (likely to delay execution)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses 32bit PE files

Classification

Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_01c59e3c-7

Compliance

barindex
Source: WirelessMedia.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: WirelessMedia.exe Static PE information: certificate valid
Source: WirelessMedia.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: F:\gs1\VS\out\binaries\x86ret\bin\i386\DPCA.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gs1\VS\out\binaries\x86ret\bin\i386\DPCA.pdb? source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaAutoServiceC3.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaAutoServiceC3.exe, 00000001.00000002.4131018854.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000001.00000000.1674756084.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000003.00000002.1793005366.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000003.00000000.1792521725.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000005.00000002.1873697861.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000005.00000000.1873221967.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaMain.pdbr source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131454423.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678608052.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gx\VS\out\binaries\x86ret\bin\i386\DPCA.pdb= source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaMain.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131454423.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678608052.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: InstallUtilLib.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gx\VS\out\binaries\x86ret\bin\i386\DPCA.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: z: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: y: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: x: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: w: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: v: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: u: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: t: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: s: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: r: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: q: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: p: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: o: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: n: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: m: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: l: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: k: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: j: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: i: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: h: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: g: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: f: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: e: Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe File opened: c: Jump to behavior
Source: unknown DNS traffic detected: query: 171.39.242.20.in-addr.arpa replaycode: Name error (3)
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa
Source: WirelessMediaMain.exe.0.dr String found in binary or memory: http://192.168.43.1:8000
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131454423.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678608052.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://192.168.43.1http://192.168.43.1:8000OKStarter-programDownload:ButtonSensor-Tastersprogramme
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://crl.globalsign.com/root.crl0G
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678687371.00000000014F0000.00000008.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131560231.00000000014F3000.00000008.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://lame.sf.net
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678687371.00000000014F0000.00000008.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131560231.00000000014F3000.00000008.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://lame.sf.net32bits64bitsBluesClassic
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp.globalsign.com/rootr103
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp.globalsign.com/rootr30;
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://ocsp.thawte.com0
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp2.globalsign.com/rootr306
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://ocsp2.globalsign.com/rootr606
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://s.symcb.com/pca3-g5.crl0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://s.symcd.com0_
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://sw.symcb.com/sw.crl0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://sw.symcd.com0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://sw1.symcb.com/sw.crt0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000015D2000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: WirelessMediaMain.exe.0.dr String found in binary or memory: http://www.videolan.org/x264.html
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: https://d.symcb.com/cps0%
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: https://d.symcb.com/rpa0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr String found in binary or memory: https://d.symcb.com/rpa0)
Source: WirelessMedia.exe, WirelessMediaMain.exe.0.dr, WirelessMediaAutoServiceC3.exe.0.dr String found in binary or memory: https://www.globalsign.com/repository/0
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: RegisterRawInputDevices memstr_254dde65-9
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process Stats: CPU usage > 49%
Source: WirelessMediaMain.exe.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: WirelessMediaMain.exe.0.dr Static PE information: Number of sections : 17 > 10
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameWirelessMediaAutoServiceC3.exe< vs WirelessMedia.exe
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameWirelessMediaMain.exe< vs WirelessMedia.exe
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameInstallUtilLib.dllT vs WirelessMedia.exe
Source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameDPCA.DLLT vs WirelessMedia.exe
Source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameInstallUtilLib.dllT vs WirelessMedia.exe
Source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameDPCA.DLLT vs WirelessMedia.exe
Source: WirelessMedia.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: clean5.winEXE@7/3@1/1
Source: C:\Users\user\Desktop\WirelessMedia.exe File created: C:\Users\user\AppData\Local\WirelessMedia Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Mutant created: \Sessions\1\BaseNamedObjects\com.WirelessMedia.mainApplicationC3
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Mutant created: \Sessions\1\BaseNamedObjects\NULL
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Mutant created: \Sessions\1\BaseNamedObjects\com.WirelessMedia.autoserviceC3
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Mutant created: \Sessions\1\BaseNamedObjects\com.WirelessMedia_Launcher.runningC3
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe System information queried: HandleInformation Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\WirelessMedia.exe "C:\Users\user\Desktop\WirelessMedia.exe"
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe"
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe"
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe" Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe" Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: avrt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: hid.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wlanapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: StartLinkC3.lnk.0.dr LNK file: ..\..\..\Desktop\WirelessMedia.exe
Source: WirelessMedia.exe Static PE information: certificate valid
Source: WirelessMedia.exe Static file information: File size 6594024 > 1048576
Source: WirelessMedia.exe Static PE information: Raw size of UPX1 is bigger than: 0x100000 < 0x63c400
Source: WirelessMedia.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: F:\gs1\VS\out\binaries\x86ret\bin\i386\DPCA.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gs1\VS\out\binaries\x86ret\bin\i386\DPCA.pdb? source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaAutoServiceC3.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaAutoServiceC3.exe, 00000001.00000002.4131018854.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000001.00000000.1674756084.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000003.00000002.1793005366.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000003.00000000.1792521725.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000005.00000002.1873697861.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe, 00000005.00000000.1873221967.00000000008B6000.00000002.00000001.01000000.00000006.sdmp, WirelessMediaAutoServiceC3.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaMain.pdbr source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131454423.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678608052.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gx\VS\out\binaries\x86ret\bin\i386\DPCA.pdb= source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: G:\git_code\Custom_new_ui\guonei\windows_new_ui\Release\WirelessMediaMain.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000003A000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131454423.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678608052.00000000013F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: InstallUtilLib.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.000000000094D000.00000040.00000001.01000000.00000003.sdmp, WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe, 00000002.00000002.4131800205.00000000016B4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: Binary string: F:\gx\VS\out\binaries\x86ret\bin\i386\DPCA.pdb source: WirelessMedia.exe, 00000000.00000002.1679451694.0000000000A8D000.00000040.00000001.01000000.00000003.sdmp, WirelessMediaMain.exe, 00000002.00000000.1678756490.00000000017F4000.00000002.00000001.01000000.00000007.sdmp, WirelessMediaMain.exe.0.dr
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .text.un
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .rodata
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .eh_fram
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .drectve
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: _RDATA
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_l
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_i
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_a
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_a
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_f
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_l
Source: WirelessMediaMain.exe.0.dr Static PE information: section name: .debug_r
Source: WirelessMediaAutoServiceC3.exe.0.dr Static PE information: section name: .text entropy: 6.9992849095309815
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: C:\Users\user\Desktop\WirelessMedia.exe File created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Jump to dropped file
Source: C:\Users\user\Desktop\WirelessMedia.exe File created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Jump to dropped file
Source: C:\Users\user\Desktop\WirelessMedia.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Auto_Agent_WirelessMediaC3 Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Auto_Agent_WirelessMediaC3 Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1459 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1472 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1424 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1425 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1492 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Window / User API: threadDelayed 1474 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1459 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1472 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1424 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1425 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1492 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe Thread sleep count: Count: 1474 delay: -10 Jump to behavior
Source: WirelessMediaMain.exe, 00000002.00000002.4132468547.00000000020E5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaAutoServiceC3.exe" Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Process created: C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe "C:\Users\user\AppData\Local\WirelessMedia\WirelessMediaMain.exe" Jump to behavior
Source: C:\Users\user\Desktop\WirelessMedia.exe Queries volume information: C:\ VolumeInformation Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs