Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://101.126.19.171:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://101.43.160.136:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://107.161.20.142:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://116.202.101.219:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://127.0.0.1:18772/handleOpenWSR?r= |
Source: build.exe, 00000002.00000002.2295681999.0000026B66DAD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://127.0.0.1:18772/handleOpenWSR?r=http://209.38.221.184:8080/get/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://129.151.109.160:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://132.145.17.167:9090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://147.28.185.29:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://159.203.174.113:8090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://167.235.70.96:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://168.138.211.88:8099 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://18.228.80.130:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://185.217.98.121:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://185.217.98.121:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://194.164.198.113:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://20.78.55.47:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://206.166.251.4:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/%79%4C%57%46%64%5F%66%72%6F%6E%74%64%65%73%6B%40%39%32%37%35%33%37%5F%72% |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/get |
Source: build.exe, 00000002.00000002.2295681999.0000026B66DAD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/get/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:8080/yLWFd_user%40927537_report.wsr |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://209.38.221.184:80802 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://38.207.174.88:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://38.60.191.38:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://41.216.183.9:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://41.216.183.9:8080/sendData |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://41.216.183.9:8080/sendData?pk=MDhCREMyMTRGMDQ3ODIxQUI0NDJDRjRDQ0IzMEMxMUQ=&ta=U29mdHdhcmU=&un |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://41.216.183.9:80802 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://41.87.207.180:9090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://46.235.26.83:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://47.96.78.224:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://51.159.4.50:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://65.49.205.24:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://67.230.176.97:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://8.216.92.21:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://8.219.110.16:9999 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://8.222.143.111:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D86000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://api.telegram.org |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line?fields=query |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.w3.or |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://138.2.92.67:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://154.9.207.142:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://185.217.98.121:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://192.99.196.191:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://5.196.181.135:443 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.tele |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D86000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot7722280561:AAEgRsAuRdqeD2qmEUjdhEM6F9R5eAxwIT4/sendMessage |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66D81000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot7722280561:AAEgRsAuRdqeD2qmEUjdhEM6F9R5eAxwIT4/sendMessage?chat_id=77347 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CAE000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2301595940.0000026B76CB6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.mozilla.org |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLK |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CAE000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2301595940.0000026B76CB6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.jXqaKJMO4ZEP |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.NYz0wxyUaYSW |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/gro.allizom.www.d |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: unknown |
Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Users\user\AppData\Local\Temp\build.exe "C:\Users\user\AppData\Local\Temp\build.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show profiles|findstr /R /C:"[ ]:[ ]" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\netsh.exe netsh wlan show profiles |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\findstr.exe findstr /R /C:"[ ]:[ ]" |
|
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show networks mode=bssid | findstr "SSID BSSID Signal" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\netsh.exe netsh wlan show networks mode=bssid |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\findstr.exe findstr "SSID BSSID Signal" |
|
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /C chcp 65001 && timeout /t 3 > NUL && DEL /F /S /Q /A "C:\Users\user\AppData\Local\Temp\build.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\timeout.exe timeout /t 3 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Users\user\AppData\Local\Temp\build.exe "C:\Users\user\AppData\Local\Temp\build.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show profiles|findstr /R /C:"[ ]:[ ]" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show networks mode=bssid | findstr "SSID BSSID Signal" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /C chcp 65001 && timeout /t 3 > NUL && DEL /F /S /Q /A "C:\Users\user\AppData\Local\Temp\build.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\netsh.exe netsh wlan show profiles |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\findstr.exe findstr /R /C:"[ ]:[ ]" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\netsh.exe netsh wlan show networks mode=bssid |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\findstr.exe findstr "SSID BSSID Signal" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\chcp.com chcp 65001 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\timeout.exe timeout /t 3 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: dlnashext.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wpdshext.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ifmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasmontr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mfc42u.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: authfwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwpolicyiomgr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: firewallapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwbase.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcmonitor.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3cfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3api.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: onex.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappprxy.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: hnetmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netshell.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netsetupapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netiohlp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nettrace.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: httpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: polstore.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshwfp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cabinet.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2pnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2p.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rpcnsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wcnnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlanapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: whhelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wshelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wevtapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wcmapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rmclient.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mobilenetworking.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: peerdistsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ktmw32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprmsg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ifmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasmontr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mfc42u.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: authfwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwpolicyiomgr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: firewallapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwbase.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcmonitor.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3cfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3api.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: onex.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappprxy.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: hnetmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netshell.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netsetupapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netiohlp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nettrace.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: httpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: polstore.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshwfp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cabinet.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2pnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2p.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rpcnsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wcnnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlanapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: whhelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wshelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wevtapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wcmapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rmclient.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mobilenetworking.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: peerdistsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ktmw32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprmsg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\chcp.com |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\timeout.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599764 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599544 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599218 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599109 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598781 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598672 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598562 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598453 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598344 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598234 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598125 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598015 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597906 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597797 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597687 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597578 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597469 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597359 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597250 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597141 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597031 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596922 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596812 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596703 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596594 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596484 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596375 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596265 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596155 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596047 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595937 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595826 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595719 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595609 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe TID: 4892 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -27670116110564310s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599764s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599544s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -599000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598344s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -598015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597797s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597141s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -597031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596922s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596265s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596155s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -596047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -595937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -595826s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -595719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 |
Thread sleep time: -595609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599764 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599544 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599218 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599109 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 599000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598781 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598672 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598562 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598453 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598344 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598234 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598125 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 598015 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597906 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597797 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597687 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597578 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597469 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597359 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597250 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597141 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 597031 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596922 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596812 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596703 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596594 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596484 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596375 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596265 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596155 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 596047 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595937 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595826 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595719 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe |
Thread delayed: delay time: 595609 |
Jump to behavior |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000000.1237262342.0000026B64C32000.00000002.00000001.01000000.00000006.sdmp, build.exe.0.dr |
Binary or memory string: qemu' |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696492231p |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - EU WestVMware20,11696492231n |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Canara Transaction PasswordVMware20,11696492231} |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: interactivebrokers.co.inVMware20,11696492231d |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: netportal.hdfcbank.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: outlook.office.comVMware20,11696492231s |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: AMC password management pageVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: interactivebrokers.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: microsoft.visualstudio.comVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - COM.HKVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Canara Change Transaction PasswordVMware20,11696492231^ |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Test URL for global passwords blocklistVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: outlook.office365.comVMware20,11696492231t |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696492231z |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: discord.comVMware20,11696492231f |
Source: build.exe, 00000002.00000002.2295304015.0000026B66887000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: global block list test formVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: dev.azure.comVMware20,11696492231j |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: www.interactivebrokers.comVMware20,11696492231} |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: www.interactivebrokers.co.inVMware20,11696492231~ |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: bankofamerica.comVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: trackpan.utiitsl.comVMware20,11696492231h |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: tasks.office.comVMware20,11696492231o |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: account.microsoft.com/profileVMware20,11696492231u |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Canara Change Transaction PasswordVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: ms.portal.azure.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: turbotax.intuit.comVMware20,11696492231t |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: secure.bankofamerica.comVMware20,11696492231|UE |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Canara Transaction PasswordVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Interactive Brokers - HKVMware20,11696492231] |