Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0040276E FindFirstFileW, |
4_2_0040276E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_00405770 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0040622B FindFirstFileW,FindClose, |
4_2_0040622B |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3304876105.0000000006DC0000.00000004.00001000.00020000.00000000.sdmp, Shipping documents 000293994900.exe, 00000004.00000002.3304583690.0000000005426000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://84.38.133.42/FZBmQQQpasdj30.bin |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.000000003578C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://concaribe.com |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.000000003578C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ftp.concaribe.com |
Source: Shipping documents 000293994900.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.0000000035711000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.0000000035711000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.0000000035711000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/ |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323810255.0000000035711000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/t |
Source: Shipping documents 000293994900.exe, 00000000.00000002.3040528511.0000000002843000.00000004.00000020.00020000.00000000.sdmp, nsj89C.tmp.0.dr, 660.jpg.0.dr |
String found in binary or memory: https://www.wikihow.com/Image:Type-Step-1-Version-6.jpg |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_004052D1 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_004052D1 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_00403358 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
4_2_00403358 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_00404B0E |
0_2_00404B0E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_0040653D |
0_2_0040653D |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00404B0E |
4_2_00404B0E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0040653D |
4_2_0040653D |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0016A214 |
4_2_0016A214 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0016E360 |
4_2_0016E360 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00164A58 |
4_2_00164A58 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0016AAAA |
4_2_0016AAAA |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00163E40 |
4_2_00163E40 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00164188 |
4_2_00164188 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0016DA78 |
4_2_0016DA78 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_37FECE21 |
4_2_37FECE21 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_37FEBB90 |
4_2_37FEBB90 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_37FEA7DC |
4_2_37FEA7DC |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D3158 |
4_2_388D3158 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388DB2F0 |
4_2_388DB2F0 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388DC240 |
4_2_388DC240 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D56A0 |
4_2_388D56A0 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D66C0 |
4_2_388D66C0 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D7E40 |
4_2_388D7E40 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D0040 |
4_2_388D0040 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D2370 |
4_2_388D2370 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388DE468 |
4_2_388DE468 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D5DB7 |
4_2_388D5DB7 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_388D7760 |
4_2_388D7760 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_38CA2B98 |
4_2_38CA2B98 |
Source: Shipping documents 000293994900.exe, 00000000.00000002.3039983496.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs Shipping documents 000293994900.exe |
Source: Shipping documents 000293994900.exe, 00000004.00000000.3037015443.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs Shipping documents 000293994900.exe |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3304583690.000000000546E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs Shipping documents 000293994900.exe |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3323761608.00000000355C9000.00000004.00000010.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs Shipping documents 000293994900.exe |
Source: Shipping documents 000293994900.exe |
Binary or memory string: OriginalFilenamekinglet.exe> vs Shipping documents 000293994900.exe |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
RDTSC instruction interceptor: First address: 6708F70 second address: 6708F70 instructions: 0x00000000 rdtsc 0x00000002 test al, al 0x00000004 cmp ax, bx 0x00000007 cmp ebx, ecx 0x00000009 jc 00007F6830F0C228h 0x0000000b cmp esi, 20C649BBh 0x00000011 test cl, 00000060h 0x00000014 inc ebp 0x00000015 cmp eax, ecx 0x00000017 inc ebx 0x00000018 cmp dl, al 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
RDTSC instruction interceptor: First address: 3188F70 second address: 3188F70 instructions: 0x00000000 rdtsc 0x00000002 test al, al 0x00000004 cmp ax, bx 0x00000007 cmp ebx, ecx 0x00000009 jc 00007F6830E09938h 0x0000000b cmp esi, 20C649BBh 0x00000011 test cl, 00000060h 0x00000014 inc ebp 0x00000015 cmp eax, ecx 0x00000017 inc ebx 0x00000018 cmp dl, al 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599766 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599547 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599438 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599312 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599094 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598969 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598859 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598750 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598641 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598531 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598418 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598311 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598093 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597965 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597808 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597703 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597589 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597156 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596594 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596484 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596375 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596156 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596047 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595937 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595828 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595719 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595609 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595498 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595391 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595141 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595031 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594922 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594812 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594703 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594594 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594484 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep count: 39 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -35971150943733603s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 428 |
Thread sleep count: 2180 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 428 |
Thread sleep count: 7666 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599438s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -599094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598969s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598641s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598418s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598311s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -598093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597965s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597808s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597589s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -597047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -596047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595498s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595391s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595141s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -595031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -594922s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -594812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -594703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -594594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe TID: 5852 |
Thread sleep time: -594484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0040276E FindFirstFileW, |
4_2_0040276E |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_00405770 |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Code function: 4_2_0040622B FindFirstFileW,FindClose, |
4_2_0040622B |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599766 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599547 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599438 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599312 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 599094 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598969 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598859 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598750 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598641 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598531 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598418 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598311 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 598093 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597965 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597808 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597703 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597589 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597156 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596594 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596484 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596375 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596156 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 596047 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595937 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595828 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595719 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595609 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595498 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595391 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595266 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595141 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 595031 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594922 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594812 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594703 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594594 |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Thread delayed: delay time: 594484 |
Jump to behavior |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3304583690.000000000546E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW5 |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3304583690.0000000005426000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW(\G |
Source: Shipping documents 000293994900.exe, 00000004.00000002.3304583690.000000000546E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Users\user\Desktop\Shipping documents 000293994900.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Shipping documents 000293994900.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |