Source: file.exe |
String found in binary or memory: http://aia.entrust.net/ts1-chain256.cer01 |
Source: file.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: file.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: explorer.exe, 00000012.00000002.3265796424.0000000005480000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.cloudflare.com/origin_ca.crl |
Source: explorer.exe, 00000012.00000003.2611556085.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354530325.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354580125.00000000013C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000002.3264505846.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2703373555.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354530325.00000000013C3000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.cloudflare.com/origin_ca.crl0 |
Source: file.exe |
String found in binary or memory: http://crl.entrust.net/2048ca.crl0 |
Source: file.exe |
String found in binary or memory: http://crl.entrust.net/ts1ca.crl0 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: file.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: file.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: file.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: file.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: explorer.exe, 00000012.00000003.2642127911.0000000001335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000002.3264409592.0000000001336000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.cloudflare.com/origin_ca |
Source: explorer.exe, 00000012.00000003.2611556085.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354530325.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354580125.00000000013C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000002.3264505846.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2703373555.00000000013BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000002.3265796424.0000000005480000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2354530325.00000000013C3000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.cloudflare.com/origin_ca0 |
Source: file.exe |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: file.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: file.exe |
String found in binary or memory: http://ocsp.entrust.net02 |
Source: file.exe |
String found in binary or memory: http://ocsp.entrust.net03 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Reynolds.com, ZeusChat.scr |
String found in binary or memory: http://www.autoitscript.com/autoit3/ |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, Reynolds.com, 0000000A.00000000.2066097134.00007FF7AA1E4000.00000002.00000001.01000000.00000007.sdmp, ZeusChat.scr, 00000010.00000000.2205239967.00007FF7520F4000.00000002.00000001.01000000.00000009.sdmp, Reynolds.com, 00000011.00000000.2255000492.00007FF7AA1E4000.00000002.00000001.01000000.00000007.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2411864117.0000000015614000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr, 00000014.00000000.2409093623.00007FF7520F4000.00000002.00000001.01000000.00000009.sdmp, ZeusChat.scr, 00000015.00000000.2415165241.00007FF7520F4000.00000002.00000001.01000000.00000009.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/X |
Source: file.exe |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: file.exe |
String found in binary or memory: http://www.entrust.net/rpa03 |
Source: explorer.exe, 00000012.00000002.3264299114.00000000012F8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/horsicq/DIE-engine |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: file.exe |
String found in binary or memory: https://www.entrust.net/rpa0 |
Source: Tech.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Reynolds.com, 0000000A.00000003.2079865873.000001A69B00A000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000012.00000003.2313532248.00000000054F0000.00000004.00000020.00020000.00000000.sdmp, ZeusChat.scr.10.dr, Reynolds.com.2.dr, Tech.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: explorer.exe, 00000012.00000002.3264299114.00000000012F8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.virustotal.com/en/search/?query= |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Americans entropy: 7.99760011473 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Satin entropy: 7.99764862118 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Rid entropy: 7.9977091016 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Eagle entropy: 7.99799114247 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Matching entropy: 7.99710399078 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Eugene entropy: 7.99803047909 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Smithsonian entropy: 7.99798906004 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Exhibits entropy: 7.99744911231 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Psychiatry entropy: 7.99633350563 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Through entropy: 7.99745463306 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Dealing entropy: 7.99815989653 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Carlo entropy: 7.99711927339 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Hotel entropy: 7.99835032646 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Landscape entropy: 7.99751935648 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Wendy entropy: 7.99809069172 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Expert entropy: 7.99780337689 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Turns entropy: 7.99807412881 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Holdem entropy: 7.99752904365 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Ai entropy: 7.99764618877 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Households entropy: 7.99708688405 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Guy entropy: 7.99699953217 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Result entropy: 7.99746905943 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Elliott entropy: 7.99808822812 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Norway entropy: 7.99778041078 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Exempt entropy: 7.99612802037 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Blvd entropy: 7.99621538932 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Jungle entropy: 7.99756807934 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Biodiversity entropy: 7.99816036628 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Chan entropy: 7.99708921533 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Typical entropy: 7.99755405965 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Def entropy: 7.99714947873 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Ebooks entropy: 7.99790460139 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Odds entropy: 7.99741776079 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Peeing entropy: 7.99746302181 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Innocent entropy: 7.99812179691 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Sucking entropy: 7.99806777596 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Resolutions entropy: 7.99730244217 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Delaware entropy: 7.99692887592 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Tm entropy: 7.99791944878 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Actual entropy: 7.99741011645 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Drums entropy: 7.99729494549 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Lambda entropy: 7.99792392141 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Same entropy: 7.99747556 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Games entropy: 7.99745741408 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Jpg entropy: 7.99792471662 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Individuals entropy: 7.99688013161 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Nervous entropy: 7.99786086382 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
File created: C:\Users\user\AppData\Local\Temp\Seafood entropy: 7.99764350559 |
Jump to dropped file |
Source: C:\Windows\SysWOW64\cmd.exe |
File created: C:\Users\user\AppData\Local\Temp\29442\l entropy: 7.99994417377 |
Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
File created: C:\Users\user\AppData\Local\CyberSphere Dynamics\M entropy: 7.99994417377 |
Jump to dropped file |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0040737E |
0_2_0040737E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00406EFE |
0_2_00406EFE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_004079A2 |
0_2_004079A2 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_004049A8 |
0_2_004049A8 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_000002453CA24F10 |
17_2_000002453CA24F10 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_000002453CA2E6F0 |
17_2_000002453CA2E6F0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_000002453CA2B550 |
17_2_000002453CA2B550 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_000002453CA25530 |
17_2_000002453CA25530 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA132BB0 |
17_2_00007FF7AA132BB0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA136C74 |
17_2_00007FF7AA136C74 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA188CB0 |
17_2_00007FF7AA188CB0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA100950 |
17_2_00007FF7AA100950 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0FB9B0 |
17_2_00007FF7AA0FB9B0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA10EAA8 |
17_2_00007FF7AA10EAA8 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA1A1F40 |
17_2_00007FF7AA1A1F40 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA122F6C |
17_2_00007FF7AA122F6C |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11BFC0 |
17_2_00007FF7AA11BFC0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA10203B |
17_2_00007FF7AA10203B |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA10F070 |
17_2_00007FF7AA10F070 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11BD44 |
17_2_00007FF7AA11BD44 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA103D70 |
17_2_00007FF7AA103D70 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA127DFC |
17_2_00007FF7AA127DFC |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA19AE10 |
17_2_00007FF7AA19AE10 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0FAEC0 |
17_2_00007FF7AA0FAEC0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA102EE0 |
17_2_00007FF7AA102EE0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA129360 |
17_2_00007FF7AA129360 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA114364 |
17_2_00007FF7AA114364 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0F24D4 |
17_2_00007FF7AA0F24D4 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11549C |
17_2_00007FF7AA11549C |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA13512C |
17_2_00007FF7AA13512C |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA19C284 |
17_2_00007FF7AA19C284 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11C28C |
17_2_00007FF7AA11C28C |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA106260 |
17_2_00007FF7AA106260 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA132290 |
17_2_00007FF7AA132290 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA128270 |
17_2_00007FF7AA128270 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0F8790 |
17_2_00007FF7AA0F8790 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11F760 |
17_2_00007FF7AA11F760 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA101820 |
17_2_00007FF7AA101820 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0F2820 |
17_2_00007FF7AA0F2820 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA0F4528 |
17_2_00007FF7AA0F4528 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA1215E0 |
17_2_00007FF7AA1215E0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA12A650 |
17_2_00007FF7AA12A650 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA136680 |
17_2_00007FF7AA136680 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA1316D0 |
17_2_00007FF7AA1316D0 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA1276EC |
17_2_00007FF7AA1276EC |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752039360 |
20_2_00007FF752039360 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752024364 |
20_2_00007FF752024364 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202549C |
20_2_00007FF75202549C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520024D4 |
20_2_00007FF7520024D4 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75204512C |
20_2_00007FF75204512C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752038270 |
20_2_00007FF752038270 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752016260 |
20_2_00007FF752016260 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202C28C |
20_2_00007FF75202C28C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752042290 |
20_2_00007FF752042290 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520AC284 |
20_2_00007FF7520AC284 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202F760 |
20_2_00007FF75202F760 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752008790 |
20_2_00007FF752008790 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752002820 |
20_2_00007FF752002820 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752011820 |
20_2_00007FF752011820 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752004528 |
20_2_00007FF752004528 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520315E0 |
20_2_00007FF7520315E0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75203A650 |
20_2_00007FF75203A650 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752046680 |
20_2_00007FF752046680 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520416D0 |
20_2_00007FF7520416D0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520376EC |
20_2_00007FF7520376EC |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752042BB0 |
20_2_00007FF752042BB0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752046C74 |
20_2_00007FF752046C74 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752098CB0 |
20_2_00007FF752098CB0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752010950 |
20_2_00007FF752010950 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75200B9B0 |
20_2_00007FF75200B9B0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75201EAA8 |
20_2_00007FF75201EAA8 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520B1F40 |
20_2_00007FF7520B1F40 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752032F6C |
20_2_00007FF752032F6C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202BFC0 |
20_2_00007FF75202BFC0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75201203B |
20_2_00007FF75201203B |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75201F070 |
20_2_00007FF75201F070 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202BD44 |
20_2_00007FF75202BD44 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752013D70 |
20_2_00007FF752013D70 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF7520AAE10 |
20_2_00007FF7520AAE10 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752037DFC |
20_2_00007FF752037DFC |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75200AEC0 |
20_2_00007FF75200AEC0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752012EE0 |
20_2_00007FF752012EE0 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 21_2_0000014D5CA9B550 |
21_2_0000014D5CA9B550 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 21_2_0000014D5CA95530 |
21_2_0000014D5CA95530 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 21_2_0000014D5CA94F10 |
21_2_0000014D5CA94F10 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 21_2_0000014D5CA9E6F0 |
21_2_0000014D5CA9E6F0 |
Source: unknown |
Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Bukkake Bukkake.cmd && Bukkake.cmd |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 29442 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Wendy + ..\Psychiatry + ..\Rid + ..\Games + ..\Norway + ..\Matching + ..\Jungle + ..\Elliott + ..\Jpg + ..\Americans + ..\Exhibits + ..\Peeing + ..\Typical + ..\Innocent + ..\Seafood + ..\Nervous + ..\Households + ..\Ai + ..\Hotel + ..\Holdem + ..\Drums + ..\Carlo + ..\Tm + ..\Landscape + ..\Resolutions + ..\Def + ..\Lambda + ..\Biodiversity + ..\Odds + ..\Smithsonian + ..\Blvd + ..\Actual + ..\Guy + ..\Expert + ..\Delaware + ..\Eagle + ..\Eugene + ..\Exempt + ..\Same + ..\Ebooks + ..\Individuals + ..\Sucking + ..\Chan + ..\Turns + ..\Satin + ..\Dealing + ..\Result + ..\Through + ..\Realized l |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com Reynolds.com l |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Windows\System32\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZeusChat.url" & echo URL="C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZeusChat.url" & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.js" |
|
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" "C:\Users\user\AppData\Local\CyberSphere Dynamics\M" |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Windows\explorer.exe explorer.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Windows\explorer.exe explorer.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Bukkake Bukkake.cmd && Bukkake.cmd |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 29442 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Wendy + ..\Psychiatry + ..\Rid + ..\Games + ..\Norway + ..\Matching + ..\Jungle + ..\Elliott + ..\Jpg + ..\Americans + ..\Exhibits + ..\Peeing + ..\Typical + ..\Innocent + ..\Seafood + ..\Nervous + ..\Households + ..\Ai + ..\Hotel + ..\Holdem + ..\Drums + ..\Carlo + ..\Tm + ..\Landscape + ..\Resolutions + ..\Def + ..\Lambda + ..\Biodiversity + ..\Odds + ..\Smithsonian + ..\Blvd + ..\Actual + ..\Guy + ..\Expert + ..\Delaware + ..\Eagle + ..\Eugene + ..\Exempt + ..\Same + ..\Ebooks + ..\Individuals + ..\Sucking + ..\Chan + ..\Turns + ..\Satin + ..\Dealing + ..\Result + ..\Through + ..\Realized l |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com Reynolds.com l |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Windows\System32\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZeusChat.url" & echo URL="C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZeusChat.url" & exit |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" "C:\Users\user\AppData\Local\CyberSphere Dynamics\M" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\choice.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: jscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: explorerframe.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_000002453CA21160 Sleep,Sleep,_amsg_exit,_initterm,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_cexit, |
17_2_000002453CA21160 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA12AD08 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
17_2_00007FF7AA12AD08 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA138E74 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
17_2_00007FF7AA138E74 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA115850 SetUnhandledExceptionFilter, |
17_2_00007FF7AA115850 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Code function: 17_2_00007FF7AA11566C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
17_2_00007FF7AA11566C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752025850 SetUnhandledExceptionFilter, |
20_2_00007FF752025850 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75202566C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
20_2_00007FF75202566C |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF75203AD08 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
20_2_00007FF75203AD08 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 20_2_00007FF752048E74 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
20_2_00007FF752048E74 |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Code function: 21_2_0000014D5CA91160 Sleep,Sleep,_amsg_exit,_initterm,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_cexit, |
21_2_0000014D5CA91160 |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtProtectVirtualMemory: Direct from: 0x7FF7AA12B26C |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtClose: Direct from: 0x7FF7AA16C3CD |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQueryInformationToken: Direct from: 0x7FF752093508 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQueryAttributesFile: Direct from: 0x7FF7AA16D642 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtProtectVirtualMemory: Direct from: 0x7FF7AA16C119 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtReadFile: Direct from: 0x7FF7AA0F7D7F |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQuerySystemInformation: Direct from: 0x7FF7AA16C4AD |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtClose: Direct from: 0x7FF75207C5C7 |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQueryAttributesFile: Direct from: 0x7FF7AA16CE4E |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtDelayExecution: Direct from: 0x7FF752011C92 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtOpenFile: Direct from: 0x7FF7AA16BF1E |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtDelayExecution: Direct from: 0x7FF7AA16DFD8 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtProtectVirtualMemory: Direct from: 0x7FF7AA118FF0 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtClose: Direct from: 0x7FF7AA16CE61 |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtProtectVirtualMemory: Direct from: 0x7FF7520083B5 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQuerySystemInformation: Direct from: 0x7FF8C88A26A1 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtClose: Direct from: 0x7FF7AA0F8693 |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQuerySystemInformation: Direct from: 0x7FF752024924 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQueryAttributesFile: Direct from: 0x7FF75207D642 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtProtectVirtualMemory: Direct from: 0x7FF75203B26C |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQueryAttributesFile: Direct from: 0x7FF75207CE4E |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtSetInformationFile: Direct from: 0x7FF7AA0F7A79 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtClose: Direct from: 0x7FF7AA16C5C7 |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtQuerySystemInformation: Direct from: 0x7FF75207C4AD |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtCreateFile: Direct from: 0x7FF7AA0F787C |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtDelayExecution: Direct from: 0x7FF75207DFD8 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtDelayExecution: Direct from: 0x7FF7AA101C92 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtWriteFile: Direct from: 0x7FF7AA16B9D7 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtClose: Direct from: 0x7FF75207C37B |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQuerySystemInformation: Direct from: 0x7FF7AA114924 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtSetInformationFile: Direct from: 0x7FF7AA0F7A91 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtProtectVirtualMemory: Direct from: 0x7FF752028FF0 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtClose: Direct from: 0x7FF7AA16C200 |
|
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtClose: Direct from: 0x7FF75207FD06 |
|
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtUnmapViewOfSection: Direct from: 0x7FF7AA16C4BD |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQueryAttributesFile: Direct from: 0x7FF7AA16C1E1 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtMapViewOfSection: Direct from: 0x7FF7AA16C508 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtOpenFile: Direct from: 0x7FF7AA16C37B |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
NtMapViewOfSection: Direct from: 0x7FF75207C4BD |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtQueryInformationToken: Direct from: 0x7FF7AA183508 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
NtProtectVirtualMemory: Direct from: 0x7FF7AA0F83B5 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Bukkake Bukkake.cmd && Bukkake.cmd |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 29442 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Wendy + ..\Psychiatry + ..\Rid + ..\Games + ..\Norway + ..\Matching + ..\Jungle + ..\Elliott + ..\Jpg + ..\Americans + ..\Exhibits + ..\Peeing + ..\Typical + ..\Innocent + ..\Seafood + ..\Nervous + ..\Households + ..\Ai + ..\Hotel + ..\Holdem + ..\Drums + ..\Carlo + ..\Tm + ..\Landscape + ..\Resolutions + ..\Def + ..\Lambda + ..\Biodiversity + ..\Odds + ..\Smithsonian + ..\Blvd + ..\Actual + ..\Guy + ..\Expert + ..\Delaware + ..\Eagle + ..\Eugene + ..\Exempt + ..\Same + ..\Ebooks + ..\Individuals + ..\Sucking + ..\Chan + ..\Turns + ..\Satin + ..\Dealing + ..\Result + ..\Through + ..\Realized l |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com Reynolds.com l |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" "C:\Users\user\AppData\Local\CyberSphere Dynamics\M" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr "C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\29442\Reynolds.com |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Users\user\AppData\Local\CyberSphere Dynamics\ZeusChat.scr |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |