Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0040276E FindFirstFileW, |
4_2_0040276E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_00405770 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0040622B FindFirstFileW,FindClose, |
4_2_0040622B |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.38.133.42 |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005AB7000.00000004.00000020.00020000.00000000.sdmp, u9aPQQIwhj.exe, 00000004.00000002.2919240219.0000000005A80000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://84.38.133.42/SaclKvrenGmYaqCeKqHVn198.bin |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005AB7000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://84.38.133.42/SaclKvrenGmYaqCeKqHVn198.binY |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035FDB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://concaribe.com |
Source: u9aPQQIwhj.exe, 00000004.00000002.2937245380.0000000038B21000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoft |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035FDB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ftp.concaribe.com |
Source: u9aPQQIwhj.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/ |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936520542.0000000035F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/t |
Source: u9aPQQIwhj.exe, 00000000.00000002.2410008030.0000000002763000.00000004.00000020.00020000.00000000.sdmp, nsw3DE5.tmp.0.dr, 660.jpg.0.dr |
String found in binary or memory: https://www.wikihow.com/Image:Type-Step-1-Version-6.jpg |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_004052D1 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageW,CreatePopupMenu,LdrInitializeThunk,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_004052D1 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,InitOnceBeginInitialize,ExitWindowsEx,ExitProcess, |
0_2_00403358 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,InitOnceBeginInitialize,ExitWindowsEx,ExitProcess, |
4_2_00403358 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_00404B0E |
0_2_00404B0E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_0040653D |
0_2_0040653D |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00404B0E |
4_2_00404B0E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0040653D |
4_2_0040653D |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0015B21D |
4_2_0015B21D |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0015E360 |
4_2_0015E360 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00154A58 |
4_2_00154A58 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00153E40 |
4_2_00153E40 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00154188 |
4_2_00154188 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_3889BB90 |
4_2_3889BB90 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_3889A7DC |
4_2_3889A7DC |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39043158 |
4_2_39043158 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_3904C240 |
4_2_3904C240 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_3904B2F0 |
4_2_3904B2F0 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39047E40 |
4_2_39047E40 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_390456A0 |
4_2_390456A0 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_390466C0 |
4_2_390466C0 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39040040 |
4_2_39040040 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39042370 |
4_2_39042370 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39045DB7 |
4_2_39045DB7 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_3904E468 |
4_2_3904E468 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39047760 |
4_2_39047760 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39412C51 |
4_2_39412C51 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_39040012 |
4_2_39040012 |
Source: u9aPQQIwhj.exe, 00000000.00000000.1653034165.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs u9aPQQIwhj.exe |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005AF4000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs u9aPQQIwhj.exe |
Source: u9aPQQIwhj.exe, 00000004.00000000.2407952768.0000000000454000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenamekinglet.exe> vs u9aPQQIwhj.exe |
Source: u9aPQQIwhj.exe, 00000004.00000002.2936077063.0000000035D09000.00000004.00000010.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs u9aPQQIwhj.exe |
Source: u9aPQQIwhj.exe |
Binary or memory string: OriginalFilenamekinglet.exe> vs u9aPQQIwhj.exe |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
RDTSC instruction interceptor: First address: 68C7DE5 second address: 68C7DE5 instructions: 0x00000000 rdtsc 0x00000002 test bh, ch 0x00000004 cmp ebx, ecx 0x00000006 jc 00007FAF0072AF56h 0x00000008 cmp edx, ebx 0x0000000a inc ebp 0x0000000b inc ebx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
RDTSC instruction interceptor: First address: 3587DE5 second address: 3587DE5 instructions: 0x00000000 rdtsc 0x00000002 test bh, ch 0x00000004 cmp ebx, ecx 0x00000006 jc 00007FAF0074E376h 0x00000008 cmp edx, ebx 0x0000000a inc ebp 0x0000000b inc ebx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599671 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599007 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598889 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598672 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598547 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598437 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598328 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598219 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598094 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597765 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597547 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597437 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597328 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597219 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597109 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597000 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596890 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596672 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596562 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596453 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596343 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596234 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596125 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596015 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595906 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595797 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595683 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595578 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595469 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595359 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595250 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595140 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595031 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594914 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594812 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594702 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594554 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594437 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -25825441703193356s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8128 |
Thread sleep count: 1934 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8128 |
Thread sleep count: 7912 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599671s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -599007s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598889s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -598094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -597000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -596015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595797s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595683s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -595031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -594914s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -594812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -594702s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -594554s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe TID: 8124 |
Thread sleep time: -594437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_00405770 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_0040622B FindFirstFileW,FindClose, |
0_2_0040622B |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 0_2_0040276E FindFirstFileW, |
0_2_0040276E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0040276E FindFirstFileW, |
4_2_0040276E |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_00405770 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_00405770 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Code function: 4_2_0040622B FindFirstFileW,FindClose, |
4_2_0040622B |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599671 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 599007 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598889 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598672 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598547 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598437 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598328 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598219 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 598094 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597765 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597547 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597437 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597328 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597219 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597109 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 597000 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596890 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596781 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596672 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596562 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596453 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596343 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596234 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596125 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 596015 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595906 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595797 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595683 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595578 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595469 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595359 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595250 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595140 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 595031 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594914 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594812 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594702 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594554 |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Thread delayed: delay time: 594437 |
Jump to behavior |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005B0B000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW}M^ |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005B0B000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: u9aPQQIwhj.exe, 00000004.00000002.2919270117.0000000005AB7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAWh3 |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Users\user\Desktop\u9aPQQIwhj.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles |
Jump to behavior |
Source: C:\Users\user\Desktop\u9aPQQIwhj.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |