Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_0040276E FindFirstFileW, |
8_2_0040276E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
8_2_00405770 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_0040622B FindFirstFileW,FindClose, |
8_2_0040622B |
Source: whatsappjpg.exe, 00000008.00000002.3824732446.0000000007A30000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://hublore.in/disha/mDdzfEwyp125.bin |
Source: whatsappjpg.exe, 00000008.00000002.3824080245.0000000005D48000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://hublore.in/disha/mDdzfEwyp125.binh( |
Source: whatsappjpg.exe, 00000008.00000002.3824080245.0000000005D48000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://hublore.in/disha/mDdzfEwyp125.binp( |
Source: whatsappjpg.exe, 00000008.00000002.3844735931.0000000036451000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: whatsappjpg.exe, 00000008.00000002.3844735931.0000000036451000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: whatsappjpg.exe, 00000008.00000002.3844735931.00000000364AF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://mail.hearing-vision.com |
Source: whatsappjpg.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: whatsappjpg.exe, 00000008.00000002.3844735931.0000000036451000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: whatsappjpg.exe, 00000000.00000002.2580955367.00000000027C5000.00000004.00000020.00020000.00000000.sdmp, 660.jpg.0.dr, nsc8B5F.tmp.0.dr |
String found in binary or memory: https://www.wikihow.com/Image:Type-Step-1-Version-6.jpg |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_004052D1 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageW,CreatePopupMenu,LdrInitializeThunk,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_004052D1 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_00403358 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
8_2_00403358 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_00404B0E |
0_2_00404B0E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_0040653D |
0_2_0040653D |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00404B0E |
8_2_00404B0E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_0040653D |
8_2_0040653D |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00164A88 |
8_2_00164A88 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00163E70 |
8_2_00163E70 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_001641B8 |
8_2_001641B8 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394AC880 |
8_2_394AC880 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394A8D28 |
8_2_394A8D28 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394A10D8 |
8_2_394A10D8 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394AB848 |
8_2_394AB848 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394AB839 |
8_2_394AB839 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394AA014 |
8_2_394AA014 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D65F8 |
8_2_394D65F8 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D0040 |
8_2_394D0040 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D8730 |
8_2_394D8730 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394DE7D0 |
8_2_394DE7D0 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D9B90 |
8_2_394D9B90 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D32B8 |
8_2_394D32B8 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394DAC48 |
8_2_394DAC48 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D8E7B |
8_2_394D8E7B |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D3598 |
8_2_394D3598 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_394D0012 |
8_2_394D0012 |
Source: whatsappjpg.exe, 00000000.00000000.1345391351.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs whatsappjpg.exe |
Source: whatsappjpg.exe, 00000008.00000000.2575394897.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs whatsappjpg.exe |
Source: whatsappjpg.exe, 00000008.00000002.3824080245.0000000005D84000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs whatsappjpg.exe |
Source: whatsappjpg.exe, 00000008.00000002.3844298833.00000000361F9000.00000004.00000010.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs whatsappjpg.exe |
Source: whatsappjpg.exe |
Binary or memory string: OriginalFilenamekinglet.exe> vs whatsappjpg.exe |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_004045C8 GetDlgItem,SetWindowTextW,LdrInitializeThunk,LdrInitializeThunk,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW, |
0_2_004045C8 |
Source: unknown |
Process created: C:\Users\user\Desktop\whatsappjpg.exe "C:\Users\user\Desktop\whatsappjpg.exe" |
|
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process created: C:\Users\user\Desktop\whatsappjpg.exe "C:\Users\user\Desktop\whatsappjpg.exe" |
|
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process created: C:\Users\user\Desktop\whatsappjpg.exe "C:\Users\user\Desktop\whatsappjpg.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
RDTSC instruction interceptor: First address: 6513551 second address: 6513551 instructions: 0x00000000 rdtsc 0x00000002 test bh, ah 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F2E7523A906h 0x00000008 inc ebp 0x00000009 inc ebx 0x0000000a test dl, bl 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
RDTSC instruction interceptor: First address: 31A3551 second address: 31A3551 instructions: 0x00000000 rdtsc 0x00000002 test bh, ah 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F2E752389A6h 0x00000008 inc ebp 0x00000009 inc ebx 0x0000000a test dl, bl 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599015 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598906 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598797 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598687 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598578 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598469 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598359 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598250 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598140 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598031 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597922 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597812 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597703 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597591 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597265 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597154 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596609 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596500 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596390 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596172 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596062 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595953 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595843 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595734 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595625 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595515 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595406 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595297 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595187 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595078 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594969 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594859 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594722 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594594 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -27670116110564310s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 920 |
Thread sleep count: 2329 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 920 |
Thread sleep count: 7522 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -599015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598797s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -598031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597922s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597591s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597265s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597154s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -597047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596500s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596390s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -596062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595843s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -595078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -594969s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -594859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -594722s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe TID: 3716 |
Thread sleep time: -594594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_0040276E FindFirstFileW, |
8_2_0040276E |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
8_2_00405770 |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Code function: 8_2_0040622B FindFirstFileW,FindClose, |
8_2_0040622B |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 599015 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598906 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598797 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598687 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598578 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598469 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598359 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598250 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598140 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 598031 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597922 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597812 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597703 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597591 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597265 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597154 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596609 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596500 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596390 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596172 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 596062 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595953 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595843 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595734 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595625 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595515 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595406 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595297 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595187 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 595078 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594969 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594859 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594722 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Thread delayed: delay time: 594594 |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Users\user\Desktop\whatsappjpg.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: dump.pcap, type: PCAP |
Source: Yara match |
File source: 00000008.00000002.3844735931.00000000364AF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000008.00000002.3844735931.0000000036483000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: whatsappjpg.exe PID: 1284, type: MEMORYSTR |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles |
Jump to behavior |
Source: C:\Users\user\Desktop\whatsappjpg.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |
Source: Yara match |
File source: dump.pcap, type: PCAP |
Source: Yara match |
File source: 00000008.00000002.3844735931.00000000364AF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000008.00000002.3844735931.0000000036483000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: whatsappjpg.exe PID: 1284, type: MEMORYSTR |