Windows Analysis Report
Move Mouse.exe

Overview

General Information

Sample name: Move Mouse.exe
Analysis ID: 1416905
MD5: de027f9d504a7c4df2c1ef36d1c8e92b
SHA1: 0c3daf79668975075cb7312c42e02b0ac24ad166
SHA256: 83862c7d91c62890ca2a1b80fd187ea6208a08917608c62d77a625e2b472399a
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

.NET source code contains potential unpacker
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: Move Mouse.exe Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: unknown HTTPS traffic detected: 185.199.111.133:443 -> 192.168.2.17:49698 version: TLS 1.2
Source: Move Mouse.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: %costura.common.logging.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: serilog=costura.serilog.dll.compressed%serilog.sinks.fileScostura.serilog.sinks.file.dll.compressedScostura.serilog.sinks.file.pdb.compressedCsv.xceed.wpf.avalondock.resourcesqcostura.sv.xceed.wpf.avalondock.resources.dll.compressed source: Move Mouse.exe
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Drawing\Microsoft.Expression.Drawing.pdb source: Move Mouse.exe, 00000000.00000002.2253682378.0000020BEE9D0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.costura.pdb.compressed source: Move Mouse.exe
Source: Binary string: *costura.common.logging.core.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: C:\Users\Eric\Source\Repos\ejensen\toggle-switch-control\WPF\ToggleSwitch\obj\Release\net46\ToggleSwitch.pdb source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: /_/src/Serilog/obj/Release/net47/Serilog.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi (NET45)\obj\Release\AudioSwitcher.AudioApi.pdb source: Move Mouse.exe, 00000000.00000002.2257235847.0000020BEEF70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: common.loggingKcostura.common.logging.dll.compressedKcostura.common.logging.pdb.compressed source: Move Mouse.exe
Source: Binary string: costura.serilog.sinks.file.pdb.compressed source: Move Mouse.exe
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi.CoreAudio (NET45)\obj\Release\AudioSwitcher.AudioApi.CoreAudio.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2257363813.0000020BEEF90000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90366000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: costura.common.logging.core.pdb.compressed source: Move Mouse.exe
Source: Binary string: /_/src/Quartz/obj/Release/net472/Quartz.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.common.logging.pdb.compressed|||Common.Logging.pdb|AB2E6312E4022E4DD37202422881A0F38B1255C7|159232 source: Move Mouse.exe
Source: Binary string: C:\Dev\ExtendedWPFToolkit\Release\Latest\OpenSource\Generated\Src\Xceed.Wpf.Toolkit\obj\Release\Xceed.Wpf.Toolkit.pdb source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi (NET45)\obj\Release\AudioSwitcher.AudioApi.pdbp source: Move Mouse.exe, 00000000.00000002.2257235847.0000020BEEF70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.serilog.sinks.file.pdb.compressed|||Serilog.Sinks.File.pdb|411C5EB1B529AEC73F6A246AB965C25248701E14|10852 source: Move Mouse.exe
Source: Binary string: /_/src/Serilog/obj/Release/net47/Serilog.pdb source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: )costura.serilog.sinks.file.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: C:\projects\serilog-sinks-file\src\Serilog.Sinks.File\obj\Release\net45\Serilog.Sinks.File.pdb source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: C:\Users\Eric\Source\Repos\ejensen\toggle-switch-control\WPF\ToggleSwitch\obj\Release\net46\ToggleSwitch.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: C:\Users\steve\source\repos\movemouse\4x\Move Mouse\obj\Debug\Move Mouse.pdb source: Move Mouse.exe
Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressedIcs-cz.xceed.wpf.avalondock.resourceswcostura.cs-cz.xceed.wpf.avalondock.resources.dll.compressedCde.xceed.wpf.avalondock.resourcesqcostura.de.xceed.wpf.avalondock.resources.dll.compressedCes.xceed.wpf.avalondock.resourcesqcostura.es.xceed.wpf.avalondock.resources.dll.compressedCfr.xceed.wpf.avalondock.resourcesqcostura.fr.xceed.wpf.avalondock.resources.dll.compressed1hardcodet.notifyicon.wpf_costura.hardcodet.notifyicon.wpf.dll.compressedChu.xceed.wpf.avalondock.resourcesqcostura.hu.xceed.wpf.avalondock.resources.dll.compressedCit.xceed.wpf.avalondock.resourcesqcostura.it.xceed.wpf.avalondock.resources.dll.compressedIja-jp.xceed.wpf.avalondock.resourceswcostura.ja-jp.xceed.wpf.avalondock.resources.dll.compressed9microsoft.expression.drawinggcostura.microsoft.expression.drawing.dll.compressedSmicrosoft.extensions.logging.abstractions source: Move Mouse.exe
Source: Binary string: C:\projects\serilog-sinks-file\src\Serilog.Sinks.File\obj\Release\net45\Serilog.Sinks.File.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: .Aaudioswitcher.audioapi.coreaudioocostura.audioswitcher.audioapi.coreaudio.dll.compressed-audioswitcher.audioapi[costura.audioswitcher.audioapi.dll.compressed'common.logging.coreUcostura.common.logging.core.dll.compressedUcostura.common.logging.core.pdb.compressed source: Move Mouse.exe
Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: Move Mouse.exe
Source: Binary string: /_/artifacts/obj/System.Diagnostics.DiagnosticSource/Release/net462/System.Diagnostics.DiagnosticSource.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: Hardcodet.NotifyIcon.Wpf.pdb source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: /_/artifacts/obj/System.Diagnostics.DiagnosticSource/Release/net462/System.Diagnostics.DiagnosticSource.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: Hardcodet.NotifyIcon.Wpf.pdbSHA256[ source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: costura.common.logging.core.pdb.compressed|||Common.Logging.Core.pdb|26BB39D69119902156BFC725CB12184117222917|11776 source: Move Mouse.exe
Source: Binary string: costura.common.logging.pdb.compressed source: Move Mouse.exe
Source: Binary string: /_/src/Quartz/obj/Release/net472/Quartz.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 4x nop then jmp 00007FF9CE14766Ah 0_2_00007FF9CE146E18
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 4x nop then jmp 00007FF9CE15445Ah 0_2_00007FF9CE14CEC8
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 4x nop then jmp 00007FF9CE14766Ah 0_2_00007FF9CE1474FC
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 4x nop then jmp 00007FF9CE4136B8h 0_2_00007FF9CE3F53E5
Source: global traffic HTTP traffic detected: GET /sw3103/movemouse/master/Update_4x.xml HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive
Source: Joe Sandbox View IP Address: 185.199.111.133 185.199.111.133
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /sw3103/movemouse/master/Update_4x.xml HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive
Source: Move Mouse.exe String found in binary or memory: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=QZTWHD9CRW5XN4http://www.movemouse.co.ukPhttps://github.com/sw3103/movemouse/wiki:https://twitter.com/movemouseFhttps://github.com/sw3103/movemouse equals www.twitter.com (Twitter)
Source: unknown DNS traffic detected: queries for: raw.githubusercontent.com
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80D34000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2234625972.0000020B80B96000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/Resources/Mouse-SystemTray-Active.ico
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80D1A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/Resources/Mouse-SystemTray-Execute.ico
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80D34000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/Resources/Mouse.ico
Source: Move Mouse.exe, 00000000.00000002.2253682378.0000020BEE9D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://expression/microsoft.expression.drawing.dll0
Source: Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingData
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingData?
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingDataT
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingData_
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingDatae
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://quartznet.sourceforge.net/JobSchedulingDatah
Source: Move Mouse.exe String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit&Xceed.Wpf.Toolkit.PropertyGrid.Editors
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit&Xceed.Wpf.Toolkit.PropertyGrid.EditorsH
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit)Xceed.Wpf.Toolkit.PropertyGrid.Attributes
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit)Xceed.Wpf.Toolkit.PropertyGrid.AttributesV
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit)Xceed.Wpf.Toolkit.PropertyGrid.Converters
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: http://schemas.xceed.com/wpf/xaml/toolkit)Xceed.Wpf.Toolkit.PropertyGrid.ConvertersU
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B8050B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.hardcodet.net/projects/wpf-notifyicon
Source: Move Mouse.exe String found in binary or memory: http://www.hardcodet.net/taskbar
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B8050B000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2234625972.0000020B80B96000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.movemouse.co.uk
Source: Move Mouse.exe String found in binary or memory: http://www.movemouse.co.uk/
Source: Move Mouse.exe String found in binary or memory: http://www.quartz-scheduler.org/documentation/quartz-2.3.0/tutorials/crontrigger.html/AddActionButto
Source: Move Mouse.exe String found in binary or memory: http://www.quartz-scheduler.org/documentation/quartz-2.3.0/tutorials/crontrigger.htmlphttps://github
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80B96000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2234625972.0000020B80D1A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.w3.or
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/dotnet/runtime
Source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/ejensen/toggle-switch-control
Source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/hardcodet/wpf-notifyicon
Source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/hardcodet/wpf-notifyicon.
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/quartznet/quartznet
Source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/serilog/serilog-sinks-file
Source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/serilog/serilog-sinks-fileC
Source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/serilog/serilog.git
Source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/serilog/serilog/pull/819.
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B8050B000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2234625972.0000020B80B96000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/sw3103/movemouse
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80257000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/sw3103/movemouse/releases/tag/v4.16.2
Source: Move Mouse.exe String found in binary or memory: https://github.com/sw3103/movemouse/wiki
Source: Move Mouse.exe String found in binary or memory: https://github.com/sw3103/movemouse/wiki/Troubleshooting).
Source: Move Mouse.exe String found in binary or memory: https://github.com/sw3103/movemouse/wiki/Troubleshooting/TwitterLink_OnMouseDown;https://twitter.com
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://raw.githubusercontent.com
Source: Move Mouse.exe, 00000000.00000002.2251701161.0000020BEE690000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://raw.githubusercontent.com/serilog/serilog-sinks-file/7eb21bd4d35d0b8b7d13e6a15851c9903ea9a46
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://raw.githubusercontent.com/sw3103/movemouse/master/Update_4x.xml
Source: Move Mouse.exe String found in binary or memory: https://raw.githubusercontent.com/sw3103/movemouse/master/Update_4x.xml)Update/LatestVersion%Update/
Source: Move Mouse.exe String found in binary or memory: https://raw.githubusercontent.com/sw3103/movemouse/master/Update_4x.xml.contact
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B8050B000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2234625972.0000020B80B96000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://twitter.com/movemouse
Source: Move Mouse.exe String found in binary or memory: https://www.paypal.com
Source: Move Mouse.exe String found in binary or memory: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=QZTWHD9CRW5XN-GitHubLink_OnMous
Source: Move Mouse.exe String found in binary or memory: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=QZTWHD9CRW5XN4http://www.movemo
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown HTTPS traffic detected: 185.199.111.133:443 -> 192.168.2.17:49698 version: TLS 1.2
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE148EF0 0_2_00007FF9CE148EF0
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3FC7A3 0_2_00007FF9CE3FC7A3
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3FC44F 0_2_00007FF9CE3FC44F
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3FC4A3 0_2_00007FF9CE3FC4A3
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3FC4CB 0_2_00007FF9CE3FC4CB
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3FC6A3 0_2_00007FF9CE3FC6A3
Source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameHardcodet.NotifyIcon.Wpf.dll> vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameSerilog.dll0 vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSystem.Diagnostics.DiagnosticSource.dll@ vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSystem.Diagnostics.DiagnosticSource.dll@ vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameHardcodet.NotifyIcon.Wpf.dll> vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQuartz.dll6 vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameAudioSwitcher.AudioApi.CoreAudio.dllb! vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameToggleSwitch.dll\ vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameQuartz.dll6 vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameXceed.Wpf.Toolkit.dllL vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameSerilog.Sinks.File.dllF vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2257363813.0000020BEEF90000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameAudioSwitcher.AudioApi.CoreAudio.dllb! vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2257235847.0000020BEEF70000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameAudioSwitcher.AudioApi.dllN vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameSystem.Diagnostics.DiagnosticSource.dll@ vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B90366000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameAudioSwitcher.AudioApi.CoreAudio.dllb! vs Move Mouse.exe
Source: Move Mouse.exe, 00000000.00000002.2253682378.0000020BEE9D0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameMicrosoft.Expression.Drawing.dll\ vs Move Mouse.exe
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: msvcp140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: windows.applicationmodel.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: msctfui.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Section loaded: gpapi.dll Jump to behavior
Source: Move Mouse.exe Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: 0.2.Move Mouse.exe.20beea00000.12.raw.unpack, TaskbarIcon.cs Task registration methods: 'CreateCustomToolTip', 'OnTaskbarCreated', 'CreateTaskbarIcon', 'CreatePopup'
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, PassThroughPropagator.cs Suspicious method names: .PassThroughPropagator.Inject
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, HttpHandlerDiagnosticListener.cs Suspicious method names: .HttpHandlerDiagnosticListener.PerformInjection
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, PassThroughPropagator.cs Suspicious method names: .PassThroughPropagator.Inject
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, LegacyPropagator.cs Suspicious method names: .LegacyPropagator.Inject
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, NoOutputPropagator.cs Suspicious method names: .NoOutputPropagator.Inject
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, LegacyPropagator.cs Suspicious method names: .LegacyPropagator.Inject
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, NoOutputPropagator.cs Suspicious method names: .NoOutputPropagator.Inject
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, DistributedContextPropagator.cs Suspicious method names: .DistributedContextPropagator.Inject
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, DistributedContextPropagator.cs Suspicious method names: .DistributedContextPropagator.InjectBaggage
Source: 0.2.Move Mouse.exe.20beed30000.13.raw.unpack, HttpHandlerDiagnosticListener.cs Suspicious method names: .HttpHandlerDiagnosticListener.PerformInjection
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, DistributedContextPropagator.cs Suspicious method names: .DistributedContextPropagator.Inject
Source: 0.2.Move Mouse.exe.20b900223f8.4.raw.unpack, DistributedContextPropagator.cs Suspicious method names: .DistributedContextPropagator.InjectBaggage
Source: classification engine Classification label: mal48.evad.winEXE@1/1@1/1
Source: C:\Users\user\Desktop\Move Mouse.exe File created: C:\Users\user\AppData\Roaming\Ellanet Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Mutant created: \Sessions\1\BaseNamedObjects\f45b30b9-9e65-4d33-a2bc-d6ba6a7500bd
Source: C:\Users\user\Desktop\Move Mouse.exe Mutant created: NULL
Source: C:\Users\user\Desktop\Move Mouse.exe Mutant created: \Sessions\1\BaseNamedObjects\ScheduleJobsThread
Source: C:\Users\user\Desktop\Move Mouse.exe File created: C:\Users\user\AppData\Local\Temp\Ellanet Jump to behavior
Source: Move Mouse.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: Move Mouse.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
Source: C:\Users\user\Desktop\Move Mouse.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Move Mouse.exe String found in binary or memory: C:\Users\steve\source\repos\movemouse\4x\Move Mouse\Views\SettingsWindow.xaml.cs5SettingsWindow_OnMouseDown'CloseButton_OnClickAAddMoveMouseCursorAction_OnClick7AddClickMouseAction_OnClick9AddScrollMouseAction_OnClickIAddPositionMouseCursorAction_OnClickCActivateApplicationAction_OnClick1AddCommandAction_OnClick/AddScriptAction_OnClick-AddSleepAction_OnClick?CommandPathBrowseButton_OnClick3AddSimpleSchedule_OnClick7AddAdvancedSchedule_OnClick-Open PowerShell Script?PowerShell Script (*.ps1)|*.ps1=ScriptPathBrowseButton_OnClick-CronHelpButton_OnClick
Source: Move Mouse.exe String found in binary or memory: C:\Users\steve\source\repos\movemouse\4x\Move Mouse\Views\SettingsWindow.xaml.cs5SettingsWindow_OnMouseDown'CloseButton_OnClickAAddMoveMouseCursorAction_OnClick7AddClickMouseAction_OnClick9AddScrollMouseAction_OnClickIAddPositionMouseCursorAction_OnClickCActivateApplicationAction_OnClick1AddCommandAction_OnClick/AddScriptAction_OnClick-AddSleepAction_OnClick?CommandPathBrowseButton_OnClick3AddSimpleSchedule_OnClick7AddAdvancedSchedule_OnClick-Open PowerShell Script?PowerShell Script (*.ps1)|*.ps1=ScriptPathBrowseButton_OnClick-CronHelpButton_OnClick
Source: Move Mouse.exe String found in binary or memory: http://www.quartz-scheduler.org/documentation/quartz-2.3.0/tutorials/crontrigger.html/AddActionButton_OnClick)HomeLink_OnMouseDown5http://www.movemouse.co.uk/ContactLink_OnMouseDown
Source: C:\Users\user\Desktop\Move Mouse.exe File read: C:\Users\user\Desktop\Move Mouse.exe:Zone.Identifier Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\Move Mouse.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: Move Mouse.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: Move Mouse.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: Move Mouse.exe Static file information: File size 2414592 > 1048576
Source: Move Mouse.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x237200
Source: Move Mouse.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Move Mouse.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: %costura.common.logging.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: serilog=costura.serilog.dll.compressed%serilog.sinks.fileScostura.serilog.sinks.file.dll.compressedScostura.serilog.sinks.file.pdb.compressedCsv.xceed.wpf.avalondock.resourcesqcostura.sv.xceed.wpf.avalondock.resources.dll.compressed source: Move Mouse.exe
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Drawing\Microsoft.Expression.Drawing.pdb source: Move Mouse.exe, 00000000.00000002.2253682378.0000020BEE9D0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.costura.pdb.compressed source: Move Mouse.exe
Source: Binary string: *costura.common.logging.core.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: C:\Users\Eric\Source\Repos\ejensen\toggle-switch-control\WPF\ToggleSwitch\obj\Release\net46\ToggleSwitch.pdb source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: /_/src/Serilog/obj/Release/net47/Serilog.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi (NET45)\obj\Release\AudioSwitcher.AudioApi.pdb source: Move Mouse.exe, 00000000.00000002.2257235847.0000020BEEF70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: common.loggingKcostura.common.logging.dll.compressedKcostura.common.logging.pdb.compressed source: Move Mouse.exe
Source: Binary string: costura.serilog.sinks.file.pdb.compressed source: Move Mouse.exe
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi.CoreAudio (NET45)\obj\Release\AudioSwitcher.AudioApi.CoreAudio.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2257363813.0000020BEEF90000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90366000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: costura.common.logging.core.pdb.compressed source: Move Mouse.exe
Source: Binary string: /_/src/Quartz/obj/Release/net472/Quartz.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.common.logging.pdb.compressed|||Common.Logging.pdb|AB2E6312E4022E4DD37202422881A0F38B1255C7|159232 source: Move Mouse.exe
Source: Binary string: C:\Dev\ExtendedWPFToolkit\Release\Latest\OpenSource\Generated\Src\Xceed.Wpf.Toolkit\obj\Release\Xceed.Wpf.Toolkit.pdb source: Move Mouse.exe, 00000000.00000002.2252543313.0000020BEE780000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: F:\Work\GitHub\AudioSwitcher\AudioSwitcher.AudioApi (NET45)\obj\Release\AudioSwitcher.AudioApi.pdbp source: Move Mouse.exe, 00000000.00000002.2257235847.0000020BEEF70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: costura.serilog.sinks.file.pdb.compressed|||Serilog.Sinks.File.pdb|411C5EB1B529AEC73F6A246AB965C25248701E14|10852 source: Move Mouse.exe
Source: Binary string: /_/src/Serilog/obj/Release/net47/Serilog.pdb source: Move Mouse.exe, 00000000.00000002.2250843544.0000020BEC630000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: )costura.serilog.sinks.file.pdb.compressed source: Move Mouse.exe, 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: C:\projects\serilog-sinks-file\src\Serilog.Sinks.File\obj\Release\net45\Serilog.Sinks.File.pdb source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: C:\Users\Eric\Source\Repos\ejensen\toggle-switch-control\WPF\ToggleSwitch\obj\Release\net46\ToggleSwitch.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2250632311.0000020BEC540000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: C:\Users\steve\source\repos\movemouse\4x\Move Mouse\obj\Debug\Move Mouse.pdb source: Move Mouse.exe
Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressedIcs-cz.xceed.wpf.avalondock.resourceswcostura.cs-cz.xceed.wpf.avalondock.resources.dll.compressedCde.xceed.wpf.avalondock.resourcesqcostura.de.xceed.wpf.avalondock.resources.dll.compressedCes.xceed.wpf.avalondock.resourcesqcostura.es.xceed.wpf.avalondock.resources.dll.compressedCfr.xceed.wpf.avalondock.resourcesqcostura.fr.xceed.wpf.avalondock.resources.dll.compressed1hardcodet.notifyicon.wpf_costura.hardcodet.notifyicon.wpf.dll.compressedChu.xceed.wpf.avalondock.resourcesqcostura.hu.xceed.wpf.avalondock.resources.dll.compressedCit.xceed.wpf.avalondock.resourcesqcostura.it.xceed.wpf.avalondock.resources.dll.compressedIja-jp.xceed.wpf.avalondock.resourceswcostura.ja-jp.xceed.wpf.avalondock.resources.dll.compressed9microsoft.expression.drawinggcostura.microsoft.expression.drawing.dll.compressedSmicrosoft.extensions.logging.abstractions source: Move Mouse.exe
Source: Binary string: C:\projects\serilog-sinks-file\src\Serilog.Sinks.File\obj\Release\net45\Serilog.Sinks.File.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2251039273.0000020BEC670000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: .Aaudioswitcher.audioapi.coreaudioocostura.audioswitcher.audioapi.coreaudio.dll.compressed-audioswitcher.audioapi[costura.audioswitcher.audioapi.dll.compressed'common.logging.coreUcostura.common.logging.core.dll.compressedUcostura.common.logging.core.pdb.compressed source: Move Mouse.exe
Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: Move Mouse.exe
Source: Binary string: /_/artifacts/obj/System.Diagnostics.DiagnosticSource/Release/net462/System.Diagnostics.DiagnosticSource.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: Hardcodet.NotifyIcon.Wpf.pdb source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: /_/artifacts/obj/System.Diagnostics.DiagnosticSource/Release/net462/System.Diagnostics.DiagnosticSource.pdb source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B9009A000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B90001000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2255409070.0000020BEED30000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: Hardcodet.NotifyIcon.Wpf.pdbSHA256[ source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: costura.common.logging.core.pdb.compressed|||Common.Logging.Core.pdb|26BB39D69119902156BFC725CB12184117222917|11776 source: Move Mouse.exe
Source: Binary string: costura.common.logging.pdb.compressed source: Move Mouse.exe
Source: Binary string: /_/src/Quartz/obj/Release/net472/Quartz.pdbSHA256 source: Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2264772996.0000020BF4960000.00000004.08000000.00040000.00000000.sdmp

Data Obfuscation

barindex
Source: Move Mouse.exe, AssemblyLoader.cs .Net Code: ReadFromEmbeddedResources System.Reflection.Assembly.Load(byte[])
Source: 0.2.Move Mouse.exe.20bec630000.8.raw.unpack, SettingValueConversions.cs .Net Code: ConvertToType
Source: Yara match File source: Move Mouse.exe, type: SAMPLE
Source: Yara match File source: 0.0.Move Mouse.exe.20bebf90000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000000.00000000.975555048.0000020BEBF92000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2234625972.0000020B80001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Move Mouse.exe PID: 2480, type: MEMORYSTR
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE147BCE pushad ; retf 0_2_00007FF9CE147BFD
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE147BFE push eax; retf 0_2_00007FF9CE147C0D
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE1404F8 push cs; retf 5F5Bh 0_2_00007FF9CE14076B
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE1401AD push E95E4D4Ch; ret 0_2_00007FF9CE1401C9
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3F3FB0 pushad ; ret 0_2_00007FF9CE3F401D
Source: C:\Users\user\Desktop\Move Mouse.exe Code function: 0_2_00007FF9CE3F61E0 push ecx; ret 0_2_00007FF9CE3F61EC
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Memory allocated: 20BEC510000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Memory allocated: 20BEDEB0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Window / User API: threadDelayed 9387 Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Window / User API: threadDelayed 438 Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe TID: 6228 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe TID: 6228 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Thread delayed: delay time: 30000 Jump to behavior
Source: Move Mouse.exe, 00000000.00000002.2262178479.0000020BF2A4F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW1832%SystemRoot%\system32\mswsock.dllt Corporation1&0$
Source: Move Mouse.exe, 00000000.00000002.2260351777.0000020BF28AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: KIH~JIH{JHGyIGGvHGFsGFFpGEEmFEDjEDCgDCBdCBAaBA@_A@?\?>>Y>==V=<<S;;:P:99M888J766G555E433B221?000<...9-,,6+**3))(0''&-%$$*#""( %
Source: C:\Users\user\Desktop\Move Mouse.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Memory allocated: page read and write | page guard Jump to behavior
Source: Move Mouse.exe, 00000000.00000002.2253838780.0000020BEEA00000.00000004.08000000.00040000.00000000.sdmp, Move Mouse.exe, 00000000.00000002.2245696411.0000020B900E4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Shell_TrayWnd
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Users\user\Desktop\Move Mouse.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.Storage.winmd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.Foundation.winmd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.InteropServices.WindowsRuntime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.InteropServices.WindowsRuntime.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.WindowsRuntime\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.WindowsRuntime.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemData\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemData.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Controls.Ribbon\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Controls.Ribbon.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Move Mouse.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs