Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00402647 FindFirstFileA, |
0_2_00402647 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00405FE4 FindFirstFileA,FindClose, |
0_2_00405FE4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_004055A0 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
0_2_004055A0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00402647 FindFirstFileA, |
4_2_00402647 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00405FE4 FindFirstFileA,FindClose, |
4_2_00405FE4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_004055A0 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
4_2_004055A0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333E10F1 lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_333E10F1 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333E6580 LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,FindFirstFileExA, |
4_2_333E6580 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0040AE51 FindFirstFileW,FindNextFileW, |
8_2_0040AE51 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00407EF8 FindFirstFileA,FindNextFileA,strlen,strlen, |
9_2_00407EF8 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00407898 FindFirstFileA,FindNextFileA,strlen,strlen, |
10_2_00407898 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.133.158.36 |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000003.1985053478.0000000000A59000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ://192.168.2.1/all/install/setup.au3https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live.com/oauth20_desktop.srfhttps://login.live.com/oauth20_logout.srfhttps://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com::MBI_SSL&response_type=token&display=windesktop&theme=win7&lc=2057&redirect_uri=https://login.live.com/oauth20_desktop.srf&lw=1&fl=wld2https://login.live.com/oauth20_authorize.srfhttps://login.live.com/oauth20_desktop.srf?lc=1033https://login.live.com/oauth20_desktop.srffile:///C:/Windows/system32/oobe/FirstLogonAnim.htmlhttps://www.google.com/accounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/loginO/? equals www.facebook.com (Facebook) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000003.1985053478.0000000000A59000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ://192.168.2.1/all/install/setup.au3https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live.com/oauth20_desktop.srfhttps://login.live.com/oauth20_logout.srfhttps://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com::MBI_SSL&response_type=token&display=windesktop&theme=win7&lc=2057&redirect_uri=https://login.live.com/oauth20_desktop.srf&lw=1&fl=wld2https://login.live.com/oauth20_authorize.srfhttps://login.live.com/oauth20_desktop.srf?lc=1033https://login.live.com/oauth20_desktop.srffile:///C:/Windows/system32/oobe/FirstLogonAnim.htmlhttps://www.google.com/accounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/loginO/? equals www.yahoo.com (Yahoo) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623393052.00000000333B0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: Software\America Online\AOL Instant Messenger (TM)\CurrentVersion\Users%s\Loginprpl-msnprpl-yahooprpl-jabberprpl-novellprpl-oscarprpl-ggprpl-ircaccounts.xmlaimaim_1icqicq_1jabberjabber_1msnmsn_1yahoogggg_1http://www.imvu.comhttp://www.ebuddy.comhttps://www.google.com equals www.ebuddy.com (eBuggy) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985865973.0000000000A5A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ccounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/loginO/? equals www.facebook.com (Facebook) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985865973.0000000000A5A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ccounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/loginO/? equals www.yahoo.com (Yahoo) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.ebuddy.com equals www.ebuddy.com (eBuggy) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
String found in binary or memory: http://www.facebook.com/ equals www.facebook.com (Facebook) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623139235.00000000332C0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: ~@:9@0123456789ABCDEFURL index.datvisited:https://www.google.com/accounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/login$ equals www.facebook.com (Facebook) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623139235.00000000332C0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: ~@:9@0123456789ABCDEFURL index.datvisited:https://www.google.com/accounts/serviceloginhttp://www.facebook.com/https://login.yahoo.com/config/login$ equals www.yahoo.com (Yahoo) |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2602167733.0000000004490000.00000004.00001000.00020000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028A2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://45.133.158.36/cvTLIRXJzBJoApmtjAY235.bin |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0B |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG3.crt0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2SecureServerCA-2.crt0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTLSRSASHA2562020CA1-1.crt0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0= |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG3.crl07 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/DigicertSHA2SecureServerCA-1.crl0? |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG3.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigicertSHA2SecureServerCA-1.crl0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://crl4.digicert.com/DigicertSHA2SecureServerCA-1.crl0~ |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028A2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp$ |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp- |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028A2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp0G |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpA |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028A2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpMG |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpN |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028A2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpTGu |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2601529101.00000000028C0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp_ |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.digicert.com0: |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.digicert.com0H |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.digicert.com0I |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.msocsp.com0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://ocsp.msocsp.com0S |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: http://www.digicert.com/CPS0~ |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.ebuddy.com |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000003.1969235766.000000000086D000.00000004.00000020.00020000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000003.1969187492.000000000086D000.00000004.00000020.00020000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.imvu.com |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623393052.00000000333B0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.imvu.comhttp://www.ebuddy.comhttps://www.google.com |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000003.1969235766.000000000086D000.00000004.00000020.00020000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000003.1969187492.000000000086D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.imvu.comppData |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623393052.00000000333B0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.imvu.comr |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985266200.0000000000193000.00000004.00000010.00020000.00000000.sdmp |
String found in binary or memory: http://www.nirsoft.net |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://www.nirsoft.net/ |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://M365CDN.nel.measure.office.net/api/report?FrontEnd=VerizonCDNWorldWide&DestinationEndpoint=P |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingaot |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingaotak |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingrms |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingth |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://aefd.nelreports.net/api/report?cat=wsb |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://config.edge.skype.com/config/v1/ODSP_Sync_Client/19.043.0304.0013?UpdateRing=Prod&OS=Win&OSV |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://cxcs.microsoft.net/api/settings/en-GB/xml/settings-tipset?release=20h1&sku=Professional&plat |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://deff.nelreports.net/api/report?cat=msn |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://ecfdb90f321c52ef6e93077f63413543.azr.footprintdns.com/apc/trans.gif?bd78002c55888096ce060c58 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://ecfdb90f321c52ef6e93077f63413543.azr.footprintdns.com/apc/trans.gif?c2fcd52267835a3e34f9ac05 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://ecs.nel.measure.office.net?TenantId=ODSP_Sync_Client&DestinationEndpoint=Edge-Prod-LAX31r5c& |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://fp-afd.azurefd.us/apc/trans.gif?69c749c200c753dfb00f5bc8299ab8eb |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://fp-afd.azurefd.us/apc/trans.gif?a2555e10569a45fe03b885d268c50da9 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://fp-as.azureedge.net/apc/trans.gif?23ecc2fb73d617d9826364f47d1067db |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://fp-as.azureedge.net/apc/trans.gif?7bac4e73e9b20fcc41dc97447167937d |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://fp.msedge.net/conf/v2/asgw/fpconfig.min.json?monitorId=asgw |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com: |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
String found in binary or memory: https://login.yahoo.com/config/login |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://logincdn.msauth.net/16.000/Converged_v22057_4HqSCTf5FFStBMz0_eIqyA2.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://logincdn.msauth.net/16.000/content/js/ConvergedLoginPaginatedStrings.en-gb_RP-iR89BipE4i7ZOq |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://logincdn.msauth.net/shared/1.0/content/js/ConvergedLogin_PCore_tSc0Su-bb7Jt0QVuF6v9Cg2.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://logincdn.msauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://oneclient.sfx.ms/PreSignInSettings/Prod/2022-09-17-00-05-23/PreSignInSettingsConfig.json?One |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://oneclient.sfx.ms/PreSignInSettings/Prod/2023-10-05-07-50-22/PreSignInSettingsConfig.json |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/update100.xml?OneDriveUpdate=d75433bcf1f9312f1975 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/741e3e8c607c445262f3add0e58b18f19e0502af.xml?OneDriveUpdate=ad62f4 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/ew-preload-inline-2523c8c1505f1172be19.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/otel-logger-104bffe9378b8041455c.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-35de8a913e.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-async-styles.a903b7d0ab82e5bd2f8a.chunk.v7.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-bootstrap-5e7af218e953d095fabf.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-bundle-3a99f64809c6780df035.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-bundle-994d8943fc9264e2f8d3.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-fluent~left-nav-rc.ac5cfbeadfd63fc27ffd.chunk.v7.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-forms-group~mru~officeforms-group-forms~officeforms |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-left-nav-rc.68ab311bcca4f86f9ef5.chunk.v7.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-mru.2ce72562ad7c0ae7059c.chunk.v7.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-vendor-bundle-ba2888a24179bf152f3d.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-vendors~left-nav-rc.169ce481376dceef3ef6.chunk.v7.c |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwa-vendors~left-nav-rc.b24d6b48aeb44c7b5bf6.chunk.v7.j |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/pwaunauth-9d8bc214ac.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/sharedfontstyles-27fa2598d8.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/sharedscripts-939520eada.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/staticpwascripts-30998bff8f.js |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/bundles/staticstylesfabric-35c34b95e3.css |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/images/content/images/hero-image-desktop-f6720a4145.jpg |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/images/content/images/lockup-mslogo-color-78c06e8898.png |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/images/content/images/microsoft-365-logo-01d5ecd01a.png |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/images/content/images/unauth-apps-image-46596a6856.png |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/images/content/images/unauth-checkmark-image-1999f0bf81.png |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/versionless/officehome/thirdpartynotice.html |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/versionless/webfonts/segoeui_regular.woff2 |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://res.cdn.office.net/officehub/versionless/webfonts/segoeui_semibold.woff2 |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
String found in binary or memory: https://www.google.com/accounts/servicelogin |
Source: bhv2DCB.tmp.8.dr |
String found in binary or memory: https://www.office.com/ |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00405109 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageA,CreatePopupMenu,LdrInitializeThunk,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,LdrInitializeThunk,SetClipboardData,CloseClipboard, |
0_2_00405109 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0040987A EmptyClipboard,wcslen,GlobalAlloc,GlobalLock,memcpy,GlobalUnlock,SetClipboardData,CloseClipboard, |
8_2_0040987A |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_004098E2 EmptyClipboard,GetFileSize,GlobalAlloc,GlobalLock,ReadFile,GlobalUnlock,SetClipboardData,GetLastError,CloseHandle,GetLastError,CloseClipboard, |
8_2_004098E2 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00406DFC EmptyClipboard,GetFileSize,GlobalAlloc,GlobalLock,ReadFile,GlobalUnlock,SetClipboardData,GetLastError,CloseHandle,GetLastError,CloseClipboard, |
9_2_00406DFC |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00406E9F EmptyClipboard,strlen,GlobalAlloc,GlobalLock,memcpy,GlobalUnlock,SetClipboardData,CloseClipboard, |
9_2_00406E9F |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004068B5 EmptyClipboard,GetFileSize,GlobalAlloc,GlobalLock,ReadFile,GlobalUnlock,SetClipboardData,GetLastError,CloseHandle,GetLastError,CloseClipboard, |
10_2_004068B5 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004072B5 EmptyClipboard,strlen,GlobalAlloc,GlobalLock,memcpy,GlobalUnlock,SetClipboardData,CloseClipboard, |
10_2_004072B5 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0040DD85 memset,CreateFileW,NtQuerySystemInformation,NtQuerySystemInformation,CloseHandle,GetCurrentProcessId,_wcsicmp,_wcsicmp,_wcsicmp,OpenProcess,GetCurrentProcess,DuplicateHandle,memset,NtQueryObject,CloseHandle,_wcsicmp,CloseHandle, |
8_2_0040DD85 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00401806 NtdllDefWindowProc_W, |
8_2_00401806 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_004018C0 NtdllDefWindowProc_W, |
8_2_004018C0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004016FD NtdllDefWindowProc_A, |
9_2_004016FD |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004017B7 NtdllDefWindowProc_A, |
9_2_004017B7 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00402CAC NtdllDefWindowProc_A, |
10_2_00402CAC |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00402D66 NtdllDefWindowProc_A, |
10_2_00402D66 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00403219 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,LdrInitializeThunk,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,LdrInitializeThunk,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_00403219 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00403219 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,LdrInitializeThunk,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,LdrInitializeThunk,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
4_2_00403219 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00404948 |
0_2_00404948 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_004062BA |
0_2_004062BA |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00404948 |
4_2_00404948 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_004062BA |
4_2_004062BA |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333F7194 |
4_2_333F7194 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333EB5C1 |
4_2_333EB5C1 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044B040 |
8_2_0044B040 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0043610D |
8_2_0043610D |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00447310 |
8_2_00447310 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044A490 |
8_2_0044A490 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0040755A |
8_2_0040755A |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0043C560 |
8_2_0043C560 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044B610 |
8_2_0044B610 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044D6C0 |
8_2_0044D6C0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_004476F0 |
8_2_004476F0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044B870 |
8_2_0044B870 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044081D |
8_2_0044081D |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00414957 |
8_2_00414957 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_004079EE |
8_2_004079EE |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00407AEB |
8_2_00407AEB |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044AA80 |
8_2_0044AA80 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00412AA9 |
8_2_00412AA9 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00404B74 |
8_2_00404B74 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00404B03 |
8_2_00404B03 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044BBD8 |
8_2_0044BBD8 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00404BE5 |
8_2_00404BE5 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00404C76 |
8_2_00404C76 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00415CFE |
8_2_00415CFE |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00416D72 |
8_2_00416D72 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00446D30 |
8_2_00446D30 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00446D8B |
8_2_00446D8B |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00406E8F |
8_2_00406E8F |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00405038 |
9_2_00405038 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0041208C |
9_2_0041208C |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004050A9 |
9_2_004050A9 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0040511A |
9_2_0040511A |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0043C13A |
9_2_0043C13A |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004051AB |
9_2_004051AB |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00449300 |
9_2_00449300 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0040D322 |
9_2_0040D322 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0044A4F0 |
9_2_0044A4F0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0043A5AB |
9_2_0043A5AB |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00413631 |
9_2_00413631 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00446690 |
9_2_00446690 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0044A730 |
9_2_0044A730 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004398D8 |
9_2_004398D8 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_004498E0 |
9_2_004498E0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0044A886 |
9_2_0044A886 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0043DA09 |
9_2_0043DA09 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00438D5E |
9_2_00438D5E |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00449ED0 |
9_2_00449ED0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0041FE83 |
9_2_0041FE83 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00430F54 |
9_2_00430F54 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004050C2 |
10_2_004050C2 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004014AB |
10_2_004014AB |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00405133 |
10_2_00405133 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004051A4 |
10_2_004051A4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00401246 |
10_2_00401246 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_0040CA46 |
10_2_0040CA46 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00405235 |
10_2_00405235 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004032C8 |
10_2_004032C8 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004222D9 |
10_2_004222D9 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00401689 |
10_2_00401689 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00402F60 |
10_2_00402F60 |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000003.1962616328.0000000032D91000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000003.1986503569.00000000028E2000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623393052.00000000333CB000.00000040.10000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000003.1966707690.00000000028CF000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000003.1986604309.00000000028E2000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
Binary or memory string: OriginalFileName vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe |
Binary or memory string: OriginalFilename vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 0000000A.00000002.1970472063.000000000041B000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenamemspass.exe8 vs APPENDIX FORM_N#U00b045013-20241120.com.exe |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence'; |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000009.00000002.1967791996.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q); |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000004.00000002.2623139235.00000000332C0000.00000040.10000000.00040000.00000000.sdmp, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger'); |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0 |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s; |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s; |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985807652.000000000096F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key)); |
Source: APPENDIX FORM_N#U00b045013-20241120.com.exe, APPENDIX FORM_N#U00b045013-20241120.com.exe, 00000008.00000002.1985341619.0000000000400000.00000040.80000000.00040000.00000000.sdmp |
Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence' |
Source: unknown |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" |
|
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" |
|
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\hhicqmxmcuubmwccmnspqit" |
|
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\rjnmrfinqcmgocyodymjbnnrmv" |
|
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\bdsfsxbheketyimsnjzkeaiancxhuh" |
|
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\hhicqmxmcuubmwccmnspqit" |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\rjnmrfinqcmgocyodymjbnnrmv" |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process created: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe "C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe" /stext "C:\Users\user\AppData\Local\Temp\bdsfsxbheketyimsnjzkeaiancxhuh" |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: pstorec.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: pstorec.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_10002D40 push eax; ret |
0_2_10002D6E |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333F1219 push esp; iretd |
4_2_333F121A |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333E2806 push ecx; ret |
4_2_333E2819 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044693D push ecx; ret |
8_2_0044694D |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044DB70 push eax; ret |
8_2_0044DB84 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0044DB70 push eax; ret |
8_2_0044DBAC |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_00451D54 push eax; ret |
8_2_00451D61 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0044B090 push eax; ret |
9_2_0044B0A4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_0044B090 push eax; ret |
9_2_0044B0CC |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00451D34 push eax; ret |
9_2_00451D41 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00444E71 push ecx; ret |
9_2_00444E81 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00414060 push eax; ret |
10_2_00414074 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00414060 push eax; ret |
10_2_0041409C |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00414039 push ecx; ret |
10_2_00414049 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_004164EB push 0000006Ah; retf |
10_2_004165C4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00416553 push 0000006Ah; retf |
10_2_004165C4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00416555 push 0000006Ah; retf |
10_2_004165C4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00402647 FindFirstFileA, |
0_2_00402647 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_00405FE4 FindFirstFileA,FindClose, |
0_2_00405FE4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 0_2_004055A0 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
0_2_004055A0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00402647 FindFirstFileA, |
4_2_00402647 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_00405FE4 FindFirstFileA,FindClose, |
4_2_00405FE4 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_004055A0 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
4_2_004055A0 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333E10F1 lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
4_2_333E10F1 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 4_2_333E6580 LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,FindFirstFileExA, |
4_2_333E6580 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 8_2_0040AE51 FindFirstFileW,FindNextFileW, |
8_2_0040AE51 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 9_2_00407EF8 FindFirstFileA,FindNextFileA,strlen,strlen, |
9_2_00407EF8 |
Source: C:\Users\user\Desktop\APPENDIX FORM_N#U00b045013-20241120.com.exe |
Code function: 10_2_00407898 FindFirstFileA,FindNextFileA,strlen,strlen, |
10_2_00407898 |