Windows Analysis Report
Xming-6-9-0-31-setup.exe

Overview

General Information

Sample name: Xming-6-9-0-31-setup.exe
Analysis ID: 1545727
MD5: 4cd12b9bec0ae19b95584650bbaf534a
SHA1: 8e232d39e7c319ef299364c04b89bd4af1baca0a
SHA256: 9fe52242d63d90c5bf4859b9de46f516c54b80bf8e94939a4986667acf6c5024
Infos:

Detection

Score: 16
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Contains functionality to register a low level keyboard hook
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality to shutdown / reboot the system
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: Xming-6-9-0-31-setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0046E2D4 FindFirstFileA,FindNextFileA,FindClose, 1_2_0046E2D4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047694C FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 1_2_0047694C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00450EA4 FindFirstFileA,GetLastError, 1_2_00450EA4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045E738 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_0045E738
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00474BD0 FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 1_2_00474BD0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045EBB4 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_0045EBB4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045D1B4 FindFirstFileA,FindNextFileA,FindClose, 1_2_0045D1B4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0048D260 FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0048D260
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_004154BC strchr,strchr,strchr,strchr,strchr,FindFirstFileA,sprintf,_stat,FindNextFileA, 6_2_004154BC
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042BCE4 recv,WSAGetLastError,_errno, 5_2_0042BCE4
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-MNUTI.tmp.1.dr String found in binary or memory: http://bugs.freedesktop.org/show_bug.cgi?id=1896
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://ekushey.org/projects/shadhinota/index.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-SHM8D.tmp.1.dr String found in binary or memory: http://en.tldp.org/HOWTO/Francophones-HOWTO.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-CA42C.tmp.1.dr String found in binary or memory: http://ferheng.org
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-SHM8D.tmp.1.dr String found in binary or memory: http://gpl.insa-lyon.fr/Dvorak-Fr/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-FTQ4P.tmp.1.dr String found in binary or memory: http://hal.csd.auth.gr/~vvas/i18n/xkb/polytonic-compose.pl
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://java.sun.com/products/jfc/tsc/articles/InputMethod/indiclayout.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-VEJUK.tmp.1.dr String found in binary or memory: http://linux.dd.com.au/quest/linux/keyboard/honeywell/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-G4TDS.tmp.1.dr String found in binary or memory: http://perso.menara.ma/~kebdani/tamazgha/gnu_amazigh.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, Xming.exe, 00000005.00000002.3281575531.00000000001B4000.00000004.00000020.00020000.00000000.sdmp, is-SB758.tmp.1.dr, Xming.0.log.5.dr String found in binary or memory: http://sourceforge.net/forum/?group_id=156984
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://sourceforge.net/forum/?group_id=156984Contact:
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-VEJUK.tmp.1.dr String found in binary or memory: http://sourceforge.net/projects/omke
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-JLGR6.tmp.1.dr String found in binary or memory: http://srpski.org/dunav/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-HFSN4.tmp.1.dr String found in binary or memory: http://sun3.mif.vu.lt/cs/TK4/lithkeyb.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-0BT9P.tmp.1.dr String found in binary or memory: http://www-lehre.informatik.uni-osnabrueck.de/~rfreund/dvorak.php
Source: is-L00DR.tmp, 00000001.00000003.2027774062.0000000002156000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/Xming
Source: is-L00DR.tmp, 00000001.00000003.2269159023.000000000065D000.00000004.00000020.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000002.2271155295.000000000065D000.00000004.00000020.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2270129401.000000000065D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingFs
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2271853220.0000000002101000.00000004.00001000.00020000.00000000.sdmp, Xming-6-9-0-31-setup.exe, 00000000.00000003.2025750199.0000000002101000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2269993649.0000000002154000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027774062.0000000002156000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2025675432.0000000002330000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027322863.00000000030F0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes$
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2025675432.0000000002330000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027322863.00000000030F0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes)
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2025675432.0000000002330000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027322863.00000000030F0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes)http://www.StraightRunning.com/XmingNotes$http://www.Strai
Source: is-L00DR.tmp, 00000001.00000002.2270319193.000000000018C000.00000004.00000010.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2268357326.0000000004C10000.00000004.00001000.00020000.00000000.sdmp, xkbcomp.exe, 00000006.00000000.2271019480.00000000004C8000.00000008.00000001.01000000.0000000D.sdmp, xkbcomp.exe, 00000006.00000002.2272807297.00000000004C9000.00000008.00000001.01000000.0000000D.sdmp, is-7UVK4.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/2
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267978246.0000000000616000.00000008.00000001.01000000.00000009.sdmp, Xming.exe, 00000005.00000002.3282346415.000000000061B000.00000008.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr, is-67AQV.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/6
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000002.3283393897.000000006CB9C000.00000008.00000001.01000000.0000000A.sdmp, is-3RNSV.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/R
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000002.3283212527.000000006248B000.00000008.00000001.01000000.0000000B.sdmp, is-N9TOO.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/d&
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/fonts.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/fonts.phpopenwinAboutDlgProc
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/index.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/index.phpwinAboutDlgProc
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/release.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.StraightRunning.com/XmingNotes/release.phpwinAboutDlgProc
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2271853220.0000000002101000.00000004.00001000.00020000.00000000.sdmp, Xming-6-9-0-31-setup.exe, 00000000.00000003.2025750199.0000000002101000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2269993649.0000000002154000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027774062.0000000002156000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes6
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2271853220.0000000002101000.00000004.00001000.00020000.00000000.sdmp, Xming-6-9-0-31-setup.exe, 00000000.00000003.2025750199.0000000002101000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2269993649.0000000002154000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000003.2027774062.0000000002156000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotes:
Source: is-L00DR.tmp, 00000001.00000003.2269620225.0000000000619000.00000004.00000020.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000002.2270989958.0000000000619000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.StraightRunning.com/XmingNotesxe
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-AT2SM.tmp.1.dr String found in binary or memory: http://www.afghanischerKulturverein.de/en/afghanComputer_en.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-710K5.tmp.1.dr String found in binary or memory: http://www.bcc.net.bd/keyboard/bsti_kb_specification.pdf
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://www.bhashaindia.com/MSProducts/XpSp2/Articles/IndicLanguageStandards.aspx
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-2ALQC.tmp.1.dr, is-SSBJH.tmp.1.dr String found in binary or memory: http://www.conectiva.com.br)
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-AT2SM.tmp.1.dr String found in binary or memory: http://www.evertype.com/standards/af/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-V1AR6.tmp.1.dr String found in binary or memory: http://www.gakartuleba.org/layouts/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-0BT9P.tmp.1.dr String found in binary or memory: http://www.goebel-consult.de/de-ergo/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-PMQOI.tmp.1.dr String found in binary or memory: http://www.hum.uit.no/a/trond/se-lat9-no-keys.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-DD00D.tmp.1.dr, is-NVB42.tmp.1.dr String found in binary or memory: http://www.hum.uit.no/a/trond/se-lat9-sefi-keys.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://www.indlinux.org/keymap/telugu.php
Source: is-L00DR.tmp, is-L00DR.tmp, 00000001.00000002.2270380494.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-L00DR.tmp.0.dr, is-0ONS4.tmp.1.dr String found in binary or memory: http://www.innosetup.com/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-G4TDS.tmp.1.dr String found in binary or memory: http://www.ircam.ma/
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-G4TDS.tmp.1.dr String found in binary or memory: http://www.ircam.ma/documents/policesclavierunicode/hapaxber.ttf
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-HFSN4.tmp.1.dr String found in binary or memory: http://www.kada.lt/litwin/Kbdlta.gif
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-FC4J3.tmp.1.dr String found in binary or memory: http://www.language-keyboard.com/languages/catalan_layout.htm
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-HAJF5.tmp.1.dr String found in binary or memory: http://www.linux-france.org/macintosh/clavier_gentoo.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-RK5SM.tmp.1.dr String found in binary or memory: http://www.nida.gov.kh
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-RUP5B.tmp.1.dr String found in binary or memory: http://www.nongnu.org/sinhala/doc/keymaps/sinhala-keyboard_3.html
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-CA42C.tmp.1.dr String found in binary or memory: http://www.pckurd.net
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-N2A44.tmp.1.dr String found in binary or memory: http://www.qamus.org/transliteration.htm
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026050551.0000000002330000.00000004.00001000.00020000.00000000.sdmp, Xming-6-9-0-31-setup.exe, 00000000.00000003.2026191239.0000000002108000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, is-L00DR.tmp, 00000001.00000002.2270380494.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-L00DR.tmp.0.dr, is-0ONS4.tmp.1.dr String found in binary or memory: http://www.remobjects.com/?ps
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026050551.0000000002330000.00000004.00001000.00020000.00000000.sdmp, Xming-6-9-0-31-setup.exe, 00000000.00000003.2026191239.0000000002108000.00000004.00001000.00020000.00000000.sdmp, is-L00DR.tmp, 00000001.00000002.2270380494.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-L00DR.tmp.0.dr, is-0ONS4.tmp.1.dr String found in binary or memory: http://www.remobjects.com/?psU
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-IO1NN.tmp.1.dr String found in binary or memory: http://www.sbl-site.org/Resources/Resources_BiblicalFonts.aspx.
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-IA46D.tmp.1.dr String found in binary or memory: http://www.sci.kz/~sairan/keyboard/kzkbd.html
Source: is-UTJTO.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/trouble.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/trouble.phpwinAboutDlgProc
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/xming.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/xming.phpwinAboutDlgProc
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/xmingrc.php
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, Xming.exe, 00000005.00000000.2267919234.0000000000596000.00000002.00000001.01000000.00000009.sdmp, is-SB758.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotes/xmingrc.phpwinAboutDlgProc
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-67AQV.tmp.1.dr String found in binary or memory: http://www.straightrunning.com/XmingNotesOLE
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://www.tamilnet99.org)
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E9LTG.tmp.1.dr String found in binary or memory: http://www.tscii.org)
Source: is-E9LTG.tmp.1.dr String found in binary or memory: http://www.unicode.org)
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-DP3US.tmp.1.dr String found in binary or memory: http://www.uznet.net/index.php?option=com_content&task=view&id=288&Itemid=58
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-E2JM7.tmp.1.dr String found in binary or memory: http://www.xs4all.nl/~koospol/public/Xmodmap-nl-deadkeys.gz
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-PMQOI.tmp.1.dr String found in binary or memory: https://bugs.freedesktop.org/show_bug.cgi?id=4397
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-VEJUK.tmp.1.dr String found in binary or memory: https://bugs.freedesktop.org/show_bug.cgi?id=7095
Source: is-L00DR.tmp, 00000001.00000003.2268357326.0000000004DA2000.00000004.00001000.00020000.00000000.sdmp, is-N5VAG.tmp.1.dr String found in binary or memory: https://bugs.freedesktop.org/show_bug.cgi?id=9541

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043407B SetWindowsHookExA 0000000D,Function_00033FB0,00000000 5_2_0043407B
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00445260 IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetOpenClipboardWindow,CloseClipboard,OpenClipboard,GetLastError,GetClipboardData,GetLastError,GlobalLock,WideCharToMultiByte,malloc,WideCharToMultiByte,_strdup,free,GlobalUnlock,free,GlobalUnlock,CloseClipboard,malloc,strcat,malloc,malloc,MultiByteToWideChar,malloc,MultiByteToWideChar,GlobalAlloc,_strdup,GlobalAlloc,GetLastError,GlobalLock,memcpy,free,strcpy,free,GlobalUnlock,SetClipboardData,free,free,SetClipboardData,SetClipboardData, 5_2_00445260
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00445260 IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetOpenClipboardWindow,CloseClipboard,OpenClipboard,GetLastError,GetClipboardData,GetLastError,GlobalLock,WideCharToMultiByte,malloc,WideCharToMultiByte,_strdup,free,GlobalUnlock,free,GlobalUnlock,CloseClipboard,malloc,strcat,malloc,malloc,MultiByteToWideChar,malloc,MultiByteToWideChar,GlobalAlloc,_strdup,GlobalAlloc,GetLastError,GlobalLock,memcpy,free,strcpy,free,GlobalUnlock,SetClipboardData,free,free,SetClipboardData,SetClipboardData, 5_2_00445260
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043605A GetClipboardOwner,OpenClipboard,EmptyClipboard,CloseClipboard,GetOpenClipboardWindow,CloseClipboard,OpenClipboard,GetLastError,EmptyClipboard,GetLastError,SetClipboardData,SetClipboardData,CloseClipboard,GetLastError, 5_2_0043605A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00444B9A ChangeClipboardChain,PostQuitMessage,GetClipboardViewer,SetClipboardViewer,GetLastError,SendMessageA,GetClipboardViewer,ChangeClipboardChain,GetClipboardViewer,SetClipboardViewer,GetLastError,ChangeClipboardChain,GetClipboardOwner,IsClipboardFormatAvailable,IsClipboardFormatAvailable,SendMessageA,GetOpenClipboardWindow,CloseClipboard,OpenClipboard,GetLastError,EmptyClipboard,GetLastError,SetClipboardData,SetClipboardData,PostMessageA,CloseClipboard,GetLastError,GetClipboardOwner,OpenClipboard,EmptyClipboard,SetClipboardData,SetClipboardData,CloseClipboard, 5_2_00444B9A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00445260 IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetOpenClipboardWindow,CloseClipboard,OpenClipboard,GetLastError,GetClipboardData,GetLastError,GlobalLock,WideCharToMultiByte,malloc,WideCharToMultiByte,_strdup,free,GlobalUnlock,free,GlobalUnlock,CloseClipboard,malloc,strcat,malloc,malloc,MultiByteToWideChar,malloc,MultiByteToWideChar,GlobalAlloc,_strdup,GlobalAlloc,GetLastError,GlobalLock,memcpy,free,strcpy,free,GlobalUnlock,SetClipboardData,free,free,SetClipboardData,SetClipboardData, 5_2_00445260
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043C5CC GetDC,CreateCompatibleDC,malloc,CreateDIBSection,GetObjectA,SelectObject,BitBlt,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,malloc,free,free,EnumThreadWindows, 5_2_0043C5CC
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043FCE0 GetPropA,RegisterWindowMessageA,SetPropA,ShowWindow,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDeviceCaps,GetWindowRect,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SetScrollInfo,SetScrollInfo,GetScrollInfo,GetScrollInfo,GetScrollInfo,SetScrollInfo,GetScrollInfo,GetScrollInfo,SetScrollInfo,GetScrollInfo,ScrollWindowEx,UpdateWindow,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,ShowCursor,GetTickCount,ShowCursor,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,KillTimer,GetCursorPos,GetSystemMetrics,GetSystemMetrics,GetTickCount,GetCursorPos,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,PostMessageA,PostMessageA,PostMessageA,GetKeyState,GetKeyState,GetKeyState,ShowWindow,SetActiveWindow,ShowWindow,ShowCursor,ShowCursor,ShowWindow,SetCursor,EnumThreadWindows,EnumThreadWindows,DefWindowProcA, 5_2_0043FCE0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042F64B strcpy,strcpy,GetKeyState,GetKeyState,GetKeyState,GetKeyState, 5_2_0042F64B
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042F629 GetTickCount,strcpy,strcpy,GetKeyState,GetKeyState,GetKeyState,GetKeyState, 5_2_0042F629
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00435945 GetKeyState,GetKeyState,GetKeyState,GetKeyState, 5_2_00435945
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00435944 GetKeyState,GetKeyState,GetKeyState,GetKeyState, 5_2_00435944
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00423B68 NtdllDefWindowProc_A, 1_2_00423B68
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004125BC NtdllDefWindowProc_A, 1_2_004125BC
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0042EBCC NtdllDefWindowProc_A, 1_2_0042EBCC
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00454CF8 PostMessageA,PostMessageA,SetForegroundWindow,NtdllDefWindowProc_A, 1_2_00454CF8
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00431AC0 memset,GetVersionExA,NtProtectVirtualMemory, 5_2_00431AC0
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_0040914C AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_0040914C
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00409180 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_00409180
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004536F0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_004536F0
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_004081A8 0_2_004081A8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004777A8 1_2_004777A8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00461C80 1_2_00461C80
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00469F50 1_2_00469F50
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00458180 1_2_00458180
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00430454 1_2_00430454
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004446E8 1_2_004446E8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004348B0 1_2_004348B0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00444AF4 1_2_00444AF4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047CC54 1_2_0047CC54
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045B078 1_2_0045B078
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00413202 1_2_00413202
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0043D2D0 1_2_0043D2D0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004832E4 1_2_004832E4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0042F9F8 1_2_0042F9F8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00443A48 1_2_00443A48
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00433BAC 1_2_00433BAC
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00463C84 1_2_00463C84
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00443FF0 1_2_00443FF0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00428A00 5_2_00428A00
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042734B 5_2_0042734B
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043FCE0 5_2_0043FCE0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00456033 5_2_00456033
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045E0D9 5_2_0045E0D9
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0046A170 5_2_0046A170
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044C126 5_2_0044C126
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004222F3 5_2_004222F3
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00464290 5_2_00464290
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045631E 5_2_0045631E
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044633B 5_2_0044633B
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004FE3D8 5_2_004FE3D8
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004663AE 5_2_004663AE
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044C4CD 5_2_0044C4CD
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045C550 5_2_0045C550
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045858F 5_2_0045858F
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044E66C 5_2_0044E66C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045670C 5_2_0045670C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00464720 5_2_00464720
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004487C9 5_2_004487C9
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004467D0 5_2_004467D0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004507F3 5_2_004507F3
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0046A99F 5_2_0046A99F
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0041AAF2 5_2_0041AAF2
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00456AAF 5_2_00456AAF
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044AB64 5_2_0044AB64
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00446BC1 5_2_00446BC1
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00466B85 5_2_00466B85
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045ECC2 5_2_0045ECC2
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00416CE6 5_2_00416CE6
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00456CF1 5_2_00456CF1
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044CCBC 5_2_0044CCBC
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00448CBD 5_2_00448CBD
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0041AD21 5_2_0041AD21
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044EE63 5_2_0044EE63
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00462EE0 5_2_00462EE0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00442EFB 5_2_00442EFB
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042CF19 5_2_0042CF19
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004CEF20 5_2_004CEF20
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00446FC4 5_2_00446FC4
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00456FBD 5_2_00456FBD
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004D10F4 5_2_004D10F4
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004230A4 5_2_004230A4
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043F150 5_2_0043F150
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004BB160 5_2_004BB160
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044D24A 5_2_0044D24A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00457225 5_2_00457225
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045923C 5_2_0045923C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045735A 5_2_0045735A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004473F3 5_2_004473F3
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004734F2 5_2_004734F2
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0046551D 5_2_0046551D
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004575CE 5_2_004575CE
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004516A1 5_2_004516A1
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044F6BD 5_2_0044F6BD
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00457851 5_2_00457851
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045D805 5_2_0045D805
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044D80E 5_2_0044D80E
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0053F8CA 5_2_0053F8CA
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00461A2B 5_2_00461A2B
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00457AC7 5_2_00457AC7
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0053BB50 5_2_0053BB50
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045DB40 5_2_0045DB40
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00403B6F 5_2_00403B6F
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0044FBC5 5_2_0044FBC5
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0045FC5C 5_2_0045FC5C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00441C5A 5_2_00441C5A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00457C06 5_2_00457C06
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00455DC7 5_2_00455DC7
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00451DE6 5_2_00451DE6
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00469D95 5_2_00469D95
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0053BDA6 5_2_0053BDA6
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0046BDB0 5_2_0046BDB0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00413E46 5_2_00413E46
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00445E70 5_2_00445E70
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00455EFD 5_2_00455EFD
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00457F5C 5_2_00457F5C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB789F7 5_2_6CB789F7
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB4ABF0 5_2_6CB4ABF0
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB47BD7 5_2_6CB47BD7
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB624E6 5_2_6CB624E6
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB58416 5_2_6CB58416
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB5D6BC 5_2_6CB5D6BC
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB65614 5_2_6CB65614
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB6E022 5_2_6CB6E022
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_6CB5F10F 5_2_6CB5F10F
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00402ED6 6_2_00402ED6
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_004431F0 6_2_004431F0
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0042938C 6_2_0042938C
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00443446 6_2_00443446
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00469413 6_2_00469413
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0042F5C2 6_2_0042F5C2
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0043C5FA 6_2_0043C5FA
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00469673 6_2_00469673
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_004106E9 6_2_004106E9
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00468750 6_2_00468750
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_00432850 6_2_00432850
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0046A95B 6_2_0046A95B
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0045396E 6_2_0045396E
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0046997E 6_2_0046997E
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0043B97C 6_2_0043B97C
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0044A92F 6_2_0044A92F
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_004259E1 6_2_004259E1
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0046ABE5 6_2_0046ABE5
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0043AC4B 6_2_0043AC4B
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00406A24 appears 33 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00403418 appears 59 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00405974 appears 98 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00455538 appears 57 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00445624 appears 58 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 004034AC appears 84 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00455348 appears 91 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 0040788C appears 37 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00445354 appears 43 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00433AC4 appears 32 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 0040369C appears 198 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00408BA4 appears 43 times
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: String function: 00451710 appears 67 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00421AB2 appears 32 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00417D80 appears 172 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00417D0B appears 117 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00450B8F appears 43 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00417E82 appears 81 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 0046E1E0 appears 248 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 0046E140 appears 160 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 0044A2C7 appears 81 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 0044A528 appears 34 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00417F85 appears 172 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 00417CC2 appears 260 times
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: String function: 0046E170 appears 82 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 0057CD90 appears 81 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 00431A0D appears 43 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 00431A23 appears 91 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 00426B96 appears 49 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 00426A68 appears 449 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 0057CF70 appears 101 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 004192F0 appears 113 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 00553C07 appears 77 times
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: String function: 0057D000 appears 39 times
Source: is-L00DR.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-L00DR.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) Intel Itanium, for MS Windows
Source: is-L00DR.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: is-L00DR.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-0ONS4.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-0ONS4.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) Intel Itanium, for MS Windows
Source: is-0ONS4.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: is-0ONS4.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026050551.0000000002330000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs Xming-6-9-0-31-setup.exe
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026050551.0000000002330000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilename6 vs Xming-6-9-0-31-setup.exe
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026191239.0000000002108000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs Xming-6-9-0-31-setup.exe
Source: Xming-6-9-0-31-setup.exe, 00000000.00000003.2026191239.0000000002108000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilename6 vs Xming-6-9-0-31-setup.exe
Source: Xming-6-9-0-31-setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: _RegDLL.tmp.1.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: classification engine Classification label: clean16.spyw.winEXE@7/807@0/1
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004B52E1 strstr,memset,CreateProcessA,GetLastError,FormatMessageA,LocalFree,WaitForSingleObject,GetExitCodeProcess,CloseHandle,CloseHandle, 5_2_004B52E1
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_0040914C AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_0040914C
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00409180 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_00409180
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004536F0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_004536F0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00453F20 GetModuleHandleA,GetProcAddress,GetDiskFreeSpaceExA,GetDiskFreeSpaceA, 1_2_00453F20
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00454308 CoCreateInstance,CoCreateInstance,SysFreeString, 1_2_00454308
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_004098C8 FindResourceA,SizeofResource,LoadResource,LockResource, 0_2_004098C8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\CYGWINX_DISPLAY:0
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe File created: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: Xming.exe String found in binary or memory: -from local-address specify the local address to connect from
Source: Xming.exe String found in binary or memory: --help
Source: Xming.exe String found in binary or memory: --help
Source: Xming.exe String found in binary or memory: -help
Source: Xming.exe String found in binary or memory: -help prints message with these options
Source: Xming.exe String found in binary or memory: -from local-address specify the local address to connect from
Source: Xming.exe String found in binary or memory: -help prints message with these options
Source: xkbcomp.exe String found in binary or memory: -?,-help Print this message
Source: xkbcomp.exe String found in binary or memory: -help
Source: xkbcomp.exe String found in binary or memory: -?,-help Print this message
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe File read: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe "C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe"
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp "C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp" /SL4 $2043A "C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe" 1923415 73728
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process created: C:\Program Files (x86)\Xming\Xming.exe "C:\Program Files (x86)\Xming\Xming.exe" :0 -clipboard -multiwindow
Source: C:\Program Files (x86)\Xming\Xming.exe Process created: C:\Program Files (x86)\Xming\xkbcomp.exe "C:\Program Files (x86)\Xming\xkbcomp" -w 1 "-RC:\Program Files (x86)\Xming\xkb" -xkm "C:\Users\user\AppData\Local\Temp\xkb_a01396" -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" "C:\Users\user\AppData\Local\Temp\server-0.xkm"
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp "C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp" /SL4 $2043A "C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe" 1923415 73728 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process created: C:\Program Files (x86)\Xming\Xming.exe "C:\Program Files (x86)\Xming\Xming.exe" :0 -clipboard -multiwindow Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Process created: C:\Program Files (x86)\Xming\xkbcomp.exe "C:\Program Files (x86)\Xming\xkbcomp" -w 1 "-RC:\Program Files (x86)\Xming\xkb" -xkm "C:\Users\user\AppData\Local\Temp\xkb_a01396" -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" "C:\Users\user\AppData\Local\Temp\server-0.xkm" Jump to behavior
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: libfreetype-6.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: opengl32.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: glu32.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: quserex.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: Xming.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Xming\Xming.exe
Source: XLaunch.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Xming\XLaunch.exe
Source: Xming on the Web.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Xming\Xming.url
Source: Uninstall Xming.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Xming\unins000.exe
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Automated click: Next >
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Xming-6-9-0-31-setup.exe Static file information: File size 2204914 > 1048576
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0044A890 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 1_2_0044A890
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00406518 push 00406555h; ret 0_2_0040654D
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_004040B5 push eax; ret 0_2_004040F1
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00404185 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00404206 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_0040C218 push eax; ret 0_2_0040C219
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_004042E8 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00404283 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00408C50 push 00408C83h; ret 0_2_00408C7B
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00407EA0 push ecx; mov dword ptr [esp], eax 0_2_00407EA5
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004098E4 push 00409921h; ret 1_2_00409919
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0040A023 push ds; ret 1_2_0040A024
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004062C4 push ecx; mov dword ptr [esp], eax 1_2_004062C5
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00430454 push ecx; mov dword ptr [esp], eax 1_2_00430459
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047A6CC push 0047A7AAh; ret 1_2_0047A7A2
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004106B4 push ecx; mov dword ptr [esp], edx 1_2_004106B9
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00450740 push 00450773h; ret 1_2_0045076B
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0041290C push 0041296Fh; ret 1_2_00412967
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004429C0 push ecx; mov dword ptr [esp], ecx 1_2_004429C4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00456D70 push 00456DB4h; ret 1_2_00456DAC
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045AD70 push ecx; mov dword ptr [esp], eax 1_2_0045AD75
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0040D00C push ecx; mov dword ptr [esp], edx 1_2_0040D00E
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00405485 push eax; ret 1_2_004054C1
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00405555 push 00405761h; ret 1_2_00405759
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0040F56C push ecx; mov dword ptr [esp], edx 1_2_0040F56E
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004055D6 push 00405761h; ret 1_2_00405759
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00405653 push 00405761h; ret 1_2_00405759
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004056B8 push 00405761h; ret 1_2_00405759
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047BC58 push ecx; mov dword ptr [esp], ecx 1_2_0047BC5D
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00419C0C push ecx; mov dword ptr [esp], ecx 1_2_00419C11
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00409FF7 push ds; ret 1_2_0040A021
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0047E604 push 6B005A5Eh; ret 5_2_0047E609
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-0ONS4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-7UVK4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe File created: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-N9TOO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_RegDLL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\run.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\libfreetype-6.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\plink.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\pthreadGC2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-M36O7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\xkbcomp.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-NF5IN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-3RNSV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\Xming.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-67AQV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\XLaunch.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\Program Files (x86)\Xming\is-SB758.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xming\Xming.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xming\XLaunch.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xming\Xming on the Web.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xming\Uninstall Xming.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00422840 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, 1_2_00422840
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00423BF0 IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_00423BF0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00423BF0 IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_00423BF0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047A09C IsIconic,GetWindowLongA,ShowWindow,ShowWindow, 1_2_0047A09C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00424178 IsIconic,SetActiveWindow, 1_2_00424178
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_004241C0 IsIconic,SetActiveWindow,SetFocus, 1_2_004241C0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00418368 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, 1_2_00418368
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0041757C IsIconic,GetCapture, 1_2_0041757C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00417CB2 IsIconic,SetWindowPos, 1_2_00417CB2
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00417CB4 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, 1_2_00417CB4
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0043C50C IsIconic,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,ScreenToClient,ScreenToClient,SetRect,GetClientRect,IntersectRect,InvalidateRect,UpdateWindow, 5_2_0043C50C
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00442EFB GetPropA,SetPropA,DestroyWindow,DeleteDC,DeleteObject,ReleaseDC,free,free,RemovePropA,ClientToScreen,GetSystemMetrics,GetSystemMetrics,KillTimer,GetTickCount,SetTimer,SetTimer,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,GetKeyState,SendMessageA,BeginPaint,BitBlt,GetLastError,FormatMessageA,LocalFree,EndPaint,GetSystemMetrics,GetSystemMetrics,GetTickCount,SetForegroundWindow,ClientToScreen,GetSystemMetrics,GetSystemMetrics,memcpy,GetSystemMetrics,GetSystemMetrics,GetCurrentProcessId,GetWindowThreadProcessId,GetPropA,IsWindowVisible,IsIconic,GetWindow,IsIconic,IsZoomed,GetClientRect,MapWindowPoints,GetSystemMetrics,GetSystemMetrics,SetCursor,GetClientRect,MapWindowPoints,GetSystemMetrics,GetSystemMetrics,DefWindowProcA, 5_2_00442EFB
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00442EFB GetPropA,SetPropA,DestroyWindow,DeleteDC,DeleteObject,ReleaseDC,free,free,RemovePropA,ClientToScreen,GetSystemMetrics,GetSystemMetrics,KillTimer,GetTickCount,SetTimer,SetTimer,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,ReleaseCapture,GetKeyState,SendMessageA,BeginPaint,BitBlt,GetLastError,FormatMessageA,LocalFree,EndPaint,GetSystemMetrics,GetSystemMetrics,GetTickCount,SetForegroundWindow,ClientToScreen,GetSystemMetrics,GetSystemMetrics,memcpy,GetSystemMetrics,GetSystemMetrics,GetCurrentProcessId,GetWindowThreadProcessId,GetPropA,IsWindowVisible,IsIconic,GetWindow,IsIconic,IsZoomed,GetClientRect,MapWindowPoints,GetSystemMetrics,GetSystemMetrics,SetCursor,GetClientRect,MapWindowPoints,GetSystemMetrics,GetSystemMetrics,DefWindowProcA, 5_2_00442EFB
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_004334F8 GetParent,IsIconic,GetDesktopWindow,GetWindowLongA,SetWindowLongA,GetWindowLongA,SetWindowLongA,GetSystemMetrics,GetWindowRect,GetWindowRect,CopyRect,OffsetRect,OffsetRect,OffsetRect,SetWindowPos,LoadIconA,GetSystemMetrics,GetSystemMetrics,LoadImageA,PostMessageA,PostMessageA, 5_2_004334F8
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00437999 GetCurrentProcessId,GetTopWindow,GetWindowThreadProcessId,GetPropA,IsIconic,GetPropA,GetWindow, 5_2_00437999
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00441C5A GetPropA,GetPropA,SetPropA,SetPropA,GetWindowRect,CreateRectRgnIndirect,SetWindowRgn,DeleteObject,SetWindowLongA,GetWindowPlacement,BeginPaint,BitBlt,GetLastError,FormatMessageA,LocalFree,EndPaint,ClientToScreen,GetSystemMetrics,GetSystemMetrics,ShowCursor,KillTimer,GetTickCount,ShowCursor,SetTimer,ShowCursor,SetTimer,SendMessageA,GetParent,IsIconic,ShowWindow,GetKeyState,SendMessageA,SendMessageA,GetParent,SetFocus,DestroyWindow,RemovePropA,RemovePropA,RemovePropA,SetPropA,GetWindowLongA,GetWindowLongA,SetRect,AdjustWindowRectEx,SetWindowLongA,GetParent,SetWindowLongA,SetWindowPos,GetForegroundWindow,GetWindowLongA,GetWindowLongA,SetWindowPos,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,memcpy,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetCurrentProcessId,GetWindowThreadProcessId,GetPropA,IsWindowVisible,IsIconic,GetWindow,GetPropA,SetCursor,DefWindowProcA, 5_2_00441C5A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00441C5A GetPropA,GetPropA,SetPropA,SetPropA,GetWindowRect,CreateRectRgnIndirect,SetWindowRgn,DeleteObject,SetWindowLongA,GetWindowPlacement,BeginPaint,BitBlt,GetLastError,FormatMessageA,LocalFree,EndPaint,ClientToScreen,GetSystemMetrics,GetSystemMetrics,ShowCursor,KillTimer,GetTickCount,ShowCursor,SetTimer,ShowCursor,SetTimer,SendMessageA,GetParent,IsIconic,ShowWindow,GetKeyState,SendMessageA,SendMessageA,GetParent,SetFocus,DestroyWindow,RemovePropA,RemovePropA,RemovePropA,SetPropA,GetWindowLongA,GetWindowLongA,SetRect,AdjustWindowRectEx,SetWindowLongA,GetParent,SetWindowLongA,SetWindowPos,GetForegroundWindow,GetWindowLongA,GetWindowLongA,SetWindowPos,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,memcpy,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetCurrentProcessId,GetWindowThreadProcessId,GetPropA,IsWindowVisible,IsIconic,GetWindow,GetPropA,SetCursor,DefWindowProcA, 5_2_00441C5A
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_00437C78 IsIconic,GetSystemMetrics,GetSystemMetrics,SetRect,GetWindowLongA,GetWindowLongA,AdjustWindowRectEx,GetWindowRect,EqualRect, 5_2_00437C78
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0044A890 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 1_2_0044A890
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Xming\Xming.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-0ONS4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-N9TOO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_RegDLL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\run.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\plink.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-M36O7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-NF5IN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-3RNSV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\is-67AQV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-6HCKB.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Xming\XLaunch.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Evasive API call chain: GetSystemTime,DecisionNodes
Source: C:\Program Files (x86)\Xming\Xming.exe API coverage: 6.6 %
Source: C:\Program Files (x86)\Xming\xkbcomp.exe API coverage: 3.7 %
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0046E2D4 FindFirstFileA,FindNextFileA,FindClose, 1_2_0046E2D4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0047694C FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 1_2_0047694C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00450EA4 FindFirstFileA,GetLastError, 1_2_00450EA4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045E738 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_0045E738
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00474BD0 FindFirstFileA,FindNextFileA,FindClose,FindFirstFileA,FindNextFileA,FindClose, 1_2_00474BD0
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045EBB4 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_0045EBB4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045D1B4 FindFirstFileA,FindNextFileA,FindClose, 1_2_0045D1B4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0048D260 FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0048D260
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_004154BC strchr,strchr,strchr,strchr,strchr,FindFirstFileA,sprintf,_stat,FindNextFileA, 6_2_004154BC
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_0040980C GetSystemInfo,VirtualQuery,VirtualProtect,VirtualProtect,VirtualQuery, 0_2_0040980C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp File opened: C:\Users\user\AppData Jump to behavior
Source: Xming.exe, 00000005.00000002.3282441882.00000000009DE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllonCC
Source: C:\Program Files (x86)\Xming\Xming.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0044A890 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 1_2_0044A890
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0040111C SetUnhandledExceptionFilter,__getmainargs,_iob,_setmode,_iob,_setmode,__p__fmode,__p__environ,_cexit,ExitProcess,_setmode,_iob, 5_2_0040111C
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Code function: 6_2_0040111C SetUnhandledExceptionFilter,__getmainargs,_iob,_setmode,_iob,_setmode,__p__fmode,__p__environ,_cexit,ExitProcess,_setmode,_iob, 6_2_0040111C
Source: C:\Program Files (x86)\Xming\Xming.exe Process created: C:\Program Files (x86)\Xming\xkbcomp.exe "c:\program files (x86)\xming\xkbcomp" -w 1 "-rc:\program files (x86)\xming\xkb" -xkm "c:\users\user\appdata\local\temp\xkb_a01396" -em1 "the xkeyboard keymap compiler (xkbcomp) reports:" -emp "> " -eml "errors from xkbcomp are not fatal to the x server" "c:\users\user\appdata\local\temp\server-0.xkm"
Source: C:\Program Files (x86)\Xming\Xming.exe Process created: C:\Program Files (x86)\Xming\xkbcomp.exe "c:\program files (x86)\xming\xkbcomp" -w 1 "-rc:\program files (x86)\xming\xkb" -xkm "c:\users\user\appdata\local\temp\xkb_a01396" -em1 "the xkeyboard keymap compiler (xkbcomp) reports:" -emp "> " -eml "errors from xkbcomp are not fatal to the x server" "c:\users\user\appdata\local\temp\server-0.xkm" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00459ACC GetVersion,GetModuleHandleA,GetProcAddress,GetProcAddress,GetProcAddress,AllocateAndInitializeSid,GetLastError,LocalFree, 1_2_00459ACC
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0057C2F0 cpuid 5_2_0057C2F0
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: GetLocaleInfoA, 0_2_0040515C
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: GetLocaleInfoA, 0_2_004051A8
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: GetLocaleInfoA, 1_2_00408500
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: GetLocaleInfoA, 1_2_0040854C
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Xming\xkbcomp.exe Queries volume information: C:\Program Files (x86)\Xming\XKeysymDB VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_0045604C GetTickCount,QueryPerformanceCounter,GetSystemTimeAsFileTime,GetCurrentProcessId,CreateNamedPipeA,GetLastError,CreateFileA,SetNamedPipeHandleState,CreateProcessA,CloseHandle,CloseHandle, 1_2_0045604C
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_004026C4 GetSystemTime, 0_2_004026C4
Source: C:\Users\user\AppData\Local\Temp\is-70FSE.tmp\is-L00DR.tmp Code function: 1_2_00453688 GetUserNameA, 1_2_00453688
Source: C:\Users\user\Desktop\Xming-6-9-0-31-setup.exe Code function: 0_2_00405C44 GetVersionExA, 0_2_00405C44
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042BEDC strtol,sprintf,getservbyname,_errno,strtol,htons,htonl,_errno,Sleep,bind,setsockopt,listen,_errno,_errno,_errno,closesocket,_errno,_errno,_errno,_errno, 5_2_0042BEDC
Source: C:\Program Files (x86)\Xming\Xming.exe Code function: 5_2_0042ACED atoi,socket,setsockopt,bind, 5_2_0042ACED
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs