Source: |
Binary string: cmd.pdbUGP source: esentutl.exe, 00000002.00000003.2054845712.00000133B7990000.00000004.00001000.00020000.00000000.sdmp, alpha.pif, 00000005.00000000.2058646531.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000005.00000002.2059253636.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000002.2060554341.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000000.2059683551.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000000.2060949975.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000002.2157971587.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000000.2158815042.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000002.2161338491.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000002.2162246691.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000000.2161703712.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000002.2163213670.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000000.2162595664.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif.2.dr |
Source: |
Binary string: ping.pdbGCTL source: esentutl.exe, 00000004.00000003.2056904803.00000256300D0000.00000004.00001000.00020000.00000000.sdmp, xpha.pif, 00000008.00000000.2061254196.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif, 00000008.00000002.2157147929.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif.4.dr |
Source: |
Binary string: cmd.pdb source: esentutl.exe, 00000002.00000003.2054845712.00000133B7990000.00000004.00001000.00020000.00000000.sdmp, alpha.pif, 00000005.00000000.2058646531.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000005.00000002.2059253636.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000002.2060554341.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000000.2059683551.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000000.2060949975.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000002.2157971587.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000000.2158815042.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000002.2161338491.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000002.2162246691.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000000.2161703712.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000002.2163213670.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000000.2162595664.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif.2.dr |
Source: |
Binary string: ping.pdb source: esentutl.exe, 00000004.00000003.2056904803.00000256300D0000.00000004.00001000.00020000.00000000.sdmp, xpha.pif, 00000008.00000000.2061254196.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif, 00000008.00000002.2157147929.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif.4.dr |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
5_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
5_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
5_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
5_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
5_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
6_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
6_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
6_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
6_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
6_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
9_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
9_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
9_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
9_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
9_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D589E4 NtQueryInformationToken,NtQueryInformationToken, |
5_2_00007FF718D589E4 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D5898C NtQueryInformationToken, |
5_2_00007FF718D5898C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D43D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, |
5_2_00007FF718D43D94 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D71538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, |
5_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D57FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, |
5_2_00007FF718D57FF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D58114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, |
5_2_00007FF718D58114 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, |
5_2_00007FF718D6BCF0 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D588C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, |
5_2_00007FF718D588C0 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D589E4 NtQueryInformationToken,NtQueryInformationToken, |
6_2_00007FF718D589E4 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D5898C NtQueryInformationToken, |
6_2_00007FF718D5898C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D43D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, |
6_2_00007FF718D43D94 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D71538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, |
6_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D57FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, |
6_2_00007FF718D57FF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D58114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, |
6_2_00007FF718D58114 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, |
6_2_00007FF718D6BCF0 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D588C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, |
6_2_00007FF718D588C0 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D57FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, |
9_2_00007FF718D57FF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D58114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, |
9_2_00007FF718D58114 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D589E4 NtQueryInformationToken,NtQueryInformationToken, |
9_2_00007FF718D589E4 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D5898C NtQueryInformationToken, |
9_2_00007FF718D5898C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D43D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, |
9_2_00007FF718D43D94 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D71538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, |
9_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, |
9_2_00007FF718D6BCF0 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D588C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, |
9_2_00007FF718D588C0 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D55554 |
5_2_00007FF718D55554 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D47D30 |
5_2_00007FF718D47D30 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4AA54 |
5_2_00007FF718D4AA54 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D537D8 |
5_2_00007FF718D537D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D48DF8 |
5_2_00007FF718D48DF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4CE10 |
5_2_00007FF718D4CE10 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D481D4 |
5_2_00007FF718D481D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6D9D0 |
5_2_00007FF718D6D9D0 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D71538 |
5_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D67F00 |
5_2_00007FF718D67F00 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D46EE4 |
5_2_00007FF718D46EE4 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4E680 |
5_2_00007FF718D4E680 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6EE88 |
5_2_00007FF718D6EE88 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D50A6C |
5_2_00007FF718D50A6C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D45240 |
5_2_00007FF718D45240 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D47650 |
5_2_00007FF718D47650 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4D250 |
5_2_00007FF718D4D250 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D49E50 |
5_2_00007FF718D49E50 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D54224 |
5_2_00007FF718D54224 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D42220 |
5_2_00007FF718D42220 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D44A30 |
5_2_00007FF718D44A30 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6AA30 |
5_2_00007FF718D6AA30 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D43410 |
5_2_00007FF718D43410 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D46BE0 |
5_2_00007FF718D46BE0 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6AFBC |
5_2_00007FF718D6AFBC |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D43F90 |
5_2_00007FF718D43F90 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D45B70 |
5_2_00007FF718D45B70 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D49B50 |
5_2_00007FF718D49B50 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4372C |
5_2_00007FF718D4372C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D48510 |
5_2_00007FF718D48510 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D4B0D8 |
5_2_00007FF718D4B0D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D518D4 |
5_2_00007FF718D518D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D41884 |
5_2_00007FF718D41884 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D42C48 |
5_2_00007FF718D42C48 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D6AC4C |
5_2_00007FF718D6AC4C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D57854 |
5_2_00007FF718D57854 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D55554 |
6_2_00007FF718D55554 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D47D30 |
6_2_00007FF718D47D30 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4AA54 |
6_2_00007FF718D4AA54 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D537D8 |
6_2_00007FF718D537D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D48DF8 |
6_2_00007FF718D48DF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4CE10 |
6_2_00007FF718D4CE10 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D481D4 |
6_2_00007FF718D481D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6D9D0 |
6_2_00007FF718D6D9D0 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D71538 |
6_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D67F00 |
6_2_00007FF718D67F00 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D46EE4 |
6_2_00007FF718D46EE4 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4E680 |
6_2_00007FF718D4E680 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6EE88 |
6_2_00007FF718D6EE88 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D50A6C |
6_2_00007FF718D50A6C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D45240 |
6_2_00007FF718D45240 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D47650 |
6_2_00007FF718D47650 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4D250 |
6_2_00007FF718D4D250 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D49E50 |
6_2_00007FF718D49E50 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D54224 |
6_2_00007FF718D54224 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D42220 |
6_2_00007FF718D42220 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D44A30 |
6_2_00007FF718D44A30 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6AA30 |
6_2_00007FF718D6AA30 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D43410 |
6_2_00007FF718D43410 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D46BE0 |
6_2_00007FF718D46BE0 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6AFBC |
6_2_00007FF718D6AFBC |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D43F90 |
6_2_00007FF718D43F90 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D45B70 |
6_2_00007FF718D45B70 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D49B50 |
6_2_00007FF718D49B50 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4372C |
6_2_00007FF718D4372C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D48510 |
6_2_00007FF718D48510 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D4B0D8 |
6_2_00007FF718D4B0D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D518D4 |
6_2_00007FF718D518D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D41884 |
6_2_00007FF718D41884 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D42C48 |
6_2_00007FF718D42C48 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D6AC4C |
6_2_00007FF718D6AC4C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D57854 |
6_2_00007FF718D57854 |
Source: C:\Users\Public\xpha.pif |
Code function: 8_2_00007FF6F7631B5C |
8_2_00007FF6F7631B5C |
Source: C:\Users\Public\xpha.pif |
Code function: 8_2_00007FF6F7631340 |
8_2_00007FF6F7631340 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D48DF8 |
9_2_00007FF718D48DF8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D55554 |
9_2_00007FF718D55554 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4AA54 |
9_2_00007FF718D4AA54 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D537D8 |
9_2_00007FF718D537D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D57854 |
9_2_00007FF718D57854 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4CE10 |
9_2_00007FF718D4CE10 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D481D4 |
9_2_00007FF718D481D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6D9D0 |
9_2_00007FF718D6D9D0 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D71538 |
9_2_00007FF718D71538 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D47D30 |
9_2_00007FF718D47D30 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D67F00 |
9_2_00007FF718D67F00 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D46EE4 |
9_2_00007FF718D46EE4 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4E680 |
9_2_00007FF718D4E680 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6EE88 |
9_2_00007FF718D6EE88 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D50A6C |
9_2_00007FF718D50A6C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D45240 |
9_2_00007FF718D45240 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D47650 |
9_2_00007FF718D47650 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4D250 |
9_2_00007FF718D4D250 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D49E50 |
9_2_00007FF718D49E50 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D54224 |
9_2_00007FF718D54224 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D42220 |
9_2_00007FF718D42220 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D44A30 |
9_2_00007FF718D44A30 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6AA30 |
9_2_00007FF718D6AA30 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D43410 |
9_2_00007FF718D43410 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D46BE0 |
9_2_00007FF718D46BE0 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6AFBC |
9_2_00007FF718D6AFBC |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D43F90 |
9_2_00007FF718D43F90 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D45B70 |
9_2_00007FF718D45B70 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D49B50 |
9_2_00007FF718D49B50 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4372C |
9_2_00007FF718D4372C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D48510 |
9_2_00007FF718D48510 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D4B0D8 |
9_2_00007FF718D4B0D8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D518D4 |
9_2_00007FF718D518D4 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D41884 |
9_2_00007FF718D41884 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D42C48 |
9_2_00007FF718D42C48 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D6AC4C |
9_2_00007FF718D6AC4C |
Source: unknown |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\iuhmzvlH.cmd" " |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\cmd.exe /d C:\\Users\\Public\\alpha.pif /o |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\ping.exe /d C:\\Users\\Public\\xpha.pif /o |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows " |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows \SysWOW64" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
|
Source: C:\Users\Public\alpha.pif |
Process created: C:\Users\Public\xpha.pif C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c del "C:\Users\Public\xpha.pif" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \SysWOW64 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\cmd.exe /d C:\\Users\\Public\\alpha.pif /o |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\ping.exe /d C:\\Users\\Public\\xpha.pif /o |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows " |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows \SysWOW64" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c del "C:\Users\Public\xpha.pif" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \SysWOW64 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \" |
Jump to behavior |
Source: C:\Users\Public\alpha.pif |
Process created: C:\Users\Public\xpha.pif C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
Jump to behavior |
Source: |
Binary string: cmd.pdbUGP source: esentutl.exe, 00000002.00000003.2054845712.00000133B7990000.00000004.00001000.00020000.00000000.sdmp, alpha.pif, 00000005.00000000.2058646531.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000005.00000002.2059253636.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000002.2060554341.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000000.2059683551.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000000.2060949975.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000002.2157971587.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000000.2158815042.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000002.2161338491.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000002.2162246691.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000000.2161703712.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000002.2163213670.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000000.2162595664.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif.2.dr |
Source: |
Binary string: ping.pdbGCTL source: esentutl.exe, 00000004.00000003.2056904803.00000256300D0000.00000004.00001000.00020000.00000000.sdmp, xpha.pif, 00000008.00000000.2061254196.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif, 00000008.00000002.2157147929.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif.4.dr |
Source: |
Binary string: cmd.pdb source: esentutl.exe, 00000002.00000003.2054845712.00000133B7990000.00000004.00001000.00020000.00000000.sdmp, alpha.pif, 00000005.00000000.2058646531.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000005.00000002.2059253636.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000002.2060554341.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000006.00000000.2059683551.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000000.2060949975.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000007.00000002.2157971587.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000000.2158815042.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 00000009.00000002.2161338491.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000002.2162246691.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000A.00000000.2161703712.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000002.2163213670.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif, 0000000B.00000000.2162595664.00007FF718D72000.00000002.00000001.01000000.00000004.sdmp, alpha.pif.2.dr |
Source: |
Binary string: ping.pdb source: esentutl.exe, 00000004.00000003.2056904803.00000256300D0000.00000004.00001000.00020000.00000000.sdmp, xpha.pif, 00000008.00000000.2061254196.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif, 00000008.00000002.2157147929.00007FF6F7634000.00000002.00000001.01000000.00000005.sdmp, xpha.pif.4.dr |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
5_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
5_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
5_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
5_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
5_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
6_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
6_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
6_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
6_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
6_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D52978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, |
9_2_00007FF718D52978 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D5823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, |
9_2_00007FF718D5823C |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D435B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, |
9_2_00007FF718D435B8 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D41560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, |
9_2_00007FF718D41560 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D67B4C FindFirstFileW,FindNextFileW,FindClose, |
9_2_00007FF718D67B4C |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D58FA4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
5_2_00007FF718D58FA4 |
Source: C:\Users\Public\alpha.pif |
Code function: 5_2_00007FF718D593B0 SetUnhandledExceptionFilter, |
5_2_00007FF718D593B0 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D58FA4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
6_2_00007FF718D58FA4 |
Source: C:\Users\Public\alpha.pif |
Code function: 6_2_00007FF718D593B0 SetUnhandledExceptionFilter, |
6_2_00007FF718D593B0 |
Source: C:\Users\Public\xpha.pif |
Code function: 8_2_00007FF6F7633840 SetUnhandledExceptionFilter, |
8_2_00007FF6F7633840 |
Source: C:\Users\Public\xpha.pif |
Code function: 8_2_00007FF6F7633644 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
8_2_00007FF6F7633644 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D58FA4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
9_2_00007FF718D58FA4 |
Source: C:\Users\Public\alpha.pif |
Code function: 9_2_00007FF718D593B0 SetUnhandledExceptionFilter, |
9_2_00007FF718D593B0 |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\cmd.exe /d C:\\Users\\Public\\alpha.pif /o |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\esentutl.exe C:\\Windows\\System32\\esentutl /y C:\\Windows\\System32\\ping.exe /d C:\\Users\\Public\\xpha.pif /o |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows " |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c mkdir "\\?\C:\Windows \SysWOW64" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c del "C:\Users\Public\xpha.pif" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \SysWOW64 |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\Public\alpha.pif C:\\Users\\Public\\alpha.pif /c rmdir "C:\Windows \" |
Jump to behavior |
Source: C:\Users\Public\alpha.pif |
Process created: C:\Users\Public\xpha.pif C:\\Users\\Public\\xpha.pif 127.0.0.1 -n 10 |
Jump to behavior |
Source: C:\Users\Public\alpha.pif |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, |
5_2_00007FF718D551EC |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, |
5_2_00007FF718D53140 |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, |
5_2_00007FF718D46EE4 |
Source: C:\Users\Public\alpha.pif |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, |
6_2_00007FF718D551EC |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, |
6_2_00007FF718D53140 |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, |
6_2_00007FF718D46EE4 |
Source: C:\Users\Public\alpha.pif |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, |
9_2_00007FF718D551EC |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, |
9_2_00007FF718D53140 |
Source: C:\Users\Public\alpha.pif |
Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, |
9_2_00007FF718D46EE4 |