Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl.thawte.com/ThawtePCA.crl0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/assured-cs-g1.crl00 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/assured-cs-g1.crl0L |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://cs-g2-crl.thawte.com/ThawteCSG2.crl0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://dywt.com.cn |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://dywt.com.cnservice |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.digicert.com0L |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.digicert.com0N |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.digicert.com0O |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://ocsp.thawte.com0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0 |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://www.openssl.org/support/faq.html |
Source: qZJOfO5jjs.exe |
String found in binary or memory: http://www.openssl.org/support/faq.htmlRAND |
Source: qZJOfO5jjs.exe |
String found in binary or memory: https://www.digicert.com/CPS0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02516210 IsWindowEnabled,SendMessageA,SendMessageA,SendMessageA,IsZoomed,SendMessageA,NtdllDefWindowProc_A, |
0_2_02516210 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02517A30 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02517A30 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02522AD0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02522AD0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251DA90 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0251DA90 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025162B0 IsWindowEnabled,SendMessageA,NtdllDefWindowProc_A, |
0_2_025162B0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02516350 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02516350 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02519340 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA,CallWindowProcA,GetCursorPos,GetWindowRect,PtInRect,CallWindowProcA, |
0_2_02519340 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02530B70 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02530B70 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02531370 GetPropA,NtdllDefWindowProc_A,IsWindowVisible,ShowWindow,NtdllDefWindowProc_A,NtdllDefWindowProc_A,SendMessageA, |
0_2_02531370 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02518310 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA, |
0_2_02518310 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251D330 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0251D330 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252D330 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0252D330 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02514BD0 NtdllDefWindowProc_A, |
0_2_02514BD0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251CBC0 GetPropA,NtdllDefWindowProc_A, |
0_2_0251CBC0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251C3F0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA,CallWindowProcA,GetCursorPos,GetWindowRect,PtInRect,CallWindowProcA, |
0_2_0251C3F0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02522BF0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02522BF0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02516010 IsWindowEnabled,SendMessageA,SendMessageA,GetWindowRect,IsRectEmpty,PtInRect,PtInRect,GetSystemMenu,GetMenuState,SendMessageA,NtdllDefWindowProc_A,PtInRect,IsIconic,PtInRect,IsZoomed,PtInRect,PtInRect,GetWindowRect, |
0_2_02516010 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252C800 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0252C800 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025148E0 NtdllDefWindowProc_A, |
0_2_025148E0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252D8E0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA, |
0_2_0252D8E0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025198B0 GetPropA,NtdllDefWindowProc_A,KillTimer,IsWindowVisible,IsIconic,SetTimer, |
0_2_025198B0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02515940 GetCursorPos,GetWindowRect,PtInRect,PtInRect,PtInRect,PtInRect,PtInRect,KillTimer,NtdllDefWindowProc_A, |
0_2_02515940 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02515900 IsWindowEnabled,EnableWindow,NtdllDefWindowProc_A, |
0_2_02515900 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02512E40 NtdllDefWindowProc_A, |
0_2_02512E40 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02521630 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,CallWindowProcA, |
0_2_02521630 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02524EA0 GetPropA,NtdllDefWindowProc_A, |
0_2_02524EA0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252FEA0 GetPropA,NtdllDefWindowProc_A,InvalidateRect,CallWindowProcA, |
0_2_0252FEA0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251F750 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0251F750 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02518710 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,GetParent, |
0_2_02518710 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252E7F0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0252E7F0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02524790 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02524790 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251E440 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0251E440 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02518CB0 GetPropA,NtdllDefWindowProc_A, |
0_2_02518CB0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025314B0 GetPropA,NtdllDefWindowProc_A, |
0_2_025314B0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251FD50 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_0251FD50 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0252FD50 GetPropA,GetPropA,NtdllDefWindowProc_A,FindWindowExA,GetPropA,GetWindowRect, |
0_2_0252FD50 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02518D40 GetPropA,RemovePropA,CallWindowProcA,NtdllDefWindowProc_A, |
0_2_02518D40 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02516560 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02516560 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02514510 NtdllDefWindowProc_A, |
0_2_02514510 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02523DA0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, |
0_2_02523DA0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00406C34 |
0_2_00406C34 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_004090A5 |
0_2_004090A5 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0040C4BB |
0_2_0040C4BB |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0040C2CB |
0_2_0040C2CB |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0040C2CC |
0_2_0040C2CC |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02512250 |
0_2_02512250 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02527BA0 |
0_2_02527BA0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02513970 |
0_2_02513970 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02538E7A |
0_2_02538E7A |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251B6E0 |
0_2_0251B6E0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02538D56 |
0_2_02538D56 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02527540 |
0_2_02527540 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_0251EDA0 |
0_2_0251EDA0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D34510 |
0_2_00D34510 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1B8D2 |
0_2_00D1B8D2 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1D0B1 |
0_2_00D1D0B1 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1D9CD |
0_2_00D1D9CD |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1A1E2 |
0_2_00D1A1E2 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D13930 |
0_2_00D13930 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D116D0 |
0_2_00D116D0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1BE44 |
0_2_00D1BE44 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D21272 |
0_2_00D21272 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D14270 |
0_2_00D14270 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D1B360 |
0_2_00D1B360 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D13F33 |
0_2_00D13F33 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: msimg32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: msvfw32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: dciman32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: ifmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: mprapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rasmontr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: mfc42u.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: authfwcfg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: fwpolicyiomgr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: firewallapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: fwbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: dhcpcmonitor.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: dot3cfg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: dot3api.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: onex.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: eappcfg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: eappprxy.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: fwcfg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: hnetmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: netshell.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: netsetupapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: netiohlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: nshhttp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: httpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: nshipsec.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: polstore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: winipsec.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: nshwfp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: cabinet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: p2pnetsh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: p2p.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rpcnsh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: whhelper.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wlancfg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wlanapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wshelper.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wevtapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: peerdistsh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wcmapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: rmclient.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: mobilenetworking.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: ktmw32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: mprmsg.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_004D2F38 push eax; ret |
0_2_004D2F56 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_004D0B80 push eax; ret |
0_2_004D0BAE |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02536100 push eax; ret |
0_2_0253612E |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025309F7 pushfd ; mov dword ptr [esp], edx |
0_2_025309F9 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0D1 push ebp; mov dword ptr [esp], edi |
0_2_00D2B0DC |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0D1 push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0F7 push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0FD push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B09E push ebp; mov dword ptr [esp], edi |
0_2_00D2B0DC |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B09E push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0B6 push dword ptr [esp+48h]; retn 004Ch |
0_2_00D2B0A4 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B0B4 push dword ptr [esp+48h]; retn 004Ch |
0_2_00D2B0A4 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D26040 push eax; ret |
0_2_00D25FF1 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B04F push ebp; mov dword ptr [esp], edi |
0_2_00D2B06B |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B04F push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B07C push dword ptr [esp+48h]; retn 004Ch |
0_2_00D2B0A4 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2C017 push ebx; ret |
0_2_00D2C023 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B43E push ebx; ret |
0_2_00D2B43F |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B03D push ebp; mov dword ptr [esp], edi |
0_2_00D2B0DC |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B03D push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D121F8 push eax; ret |
0_2_00D2D3E6 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B1AC push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B155 push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B15E push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B17F push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B114 push eax; ret |
0_2_00D2B2E0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B11E push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B132 push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B130 push dword ptr [esp+48h]; retn 004Ch |
0_2_00D2B0A4 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D126CE push ebx; ret |
0_2_00D126D2 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D2B2F3 push eax; ret |
0_2_00D2B154 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02533070 IsWindowVisible,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,IsRectEmpty,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsZoomed,IsRectEmpty, |
0_2_02533070 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02533070 IsWindowVisible,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,IsRectEmpty,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsZoomed,IsRectEmpty, |
0_2_02533070 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02516010 IsWindowEnabled,SendMessageA,SendMessageA,GetWindowRect,IsRectEmpty,PtInRect,PtInRect,GetSystemMenu,GetMenuState,SendMessageA,NtdllDefWindowProc_A,PtInRect,IsIconic,PtInRect,IsZoomed,PtInRect,PtInRect,GetWindowRect, |
0_2_02516010 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02531800 IsZoomed,SendMessageA,IsIconic,SendMessageA,SendMessageA,GetSystemMenu,GetMenuState,SendMessageA,SendMessageA,KillTimer,GetMenuItemID,SendMessageA,CallWindowProcA, |
0_2_02531800 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_025198B0 GetPropA,NtdllDefWindowProc_A,KillTimer,IsWindowVisible,IsIconic,SetTimer, |
0_2_025198B0 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02514E30 IsWindowVisible,GetWindowRect,CreateCompatibleDC,SelectObject,SelectObject,SetBkMode,SelectObject,SetTextColor,DrawIconEx,GetWindowTextA,DrawTextA,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,SelectObject,DeleteDC,CreateCompatibleDC,SelectObject,DeleteObject, |
0_2_02514E30 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_02535780 IsIconic,IsZoomed,IsRectEmpty,IsWindowVisible, |
0_2_02535780 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D13F33 RtlEncodePointer,__initp_misc_winsig,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, |
0_2_00D13F33 |
Source: C:\Users\user\Desktop\qZJOfO5jjs.exe |
Code function: 0_2_00D18F6A RtlEncodePointer,RtlEncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,IsDebuggerPresent,OutputDebugStringW,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer, |
0_2_00D18F6A |