Source: MSBuild.exe, 00000003.00000002.2519177655.000002592BFB3000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357B95000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357C03000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BF0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BA8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357ADC000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357B82000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.000001618010A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801B0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801C4000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801D7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.com |
Source: MSBuild.exe, 0000000D.00000002.3229739212.00000161801D7000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161800FA000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org |
Source: MSBuild.exe, 00000003.00000002.2519177655.000002592BEA1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.00000183579D1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.0000016180001000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3235921937.00000161FBD46000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/ |
Source: MSBuild.exe, 00000003.00000002.2519004275.000002592BD20000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/A |
Source: MSBuild.exe, 0000000D.00000002.3235921937.00000161FBD46000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/P6 |
Source: Pnihosiyvr.exe, 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CF85000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D298BAB000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80380000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/q |
Source: MSBuild.exe, 0000000C.00000002.3069095152.0000018370213000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoftS |
Source: MSBuild.exe, 0000000C.00000002.3064626577.0000018357B95000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357AFC000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357C03000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BF0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BA8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357B82000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801B0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801C4000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.000001618012D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://reallyfreegeoip.org |
Source: Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CC01000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2519177655.000002592BEA1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D2987F1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80001000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.00000183579D1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.0000016180001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Amcache.hve.6.dr |
String found in binary or memory: http://upx.sf.net |
Source: Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CC01000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D2987F1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://cdn.discordapp.com |
Source: Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CC01000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D2987F1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://cdn.discordapp.com/attachments/1223189307423064096/1227506231204253746/Vfjvqmgnpj.mp3?ex=662 |
Source: Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: MSBuild.exe, 0000000C.00000002.3064626577.0000018357B2A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357B95000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357C03000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BF0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BA8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357BBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357ADC000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357B82000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.000001618010A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801B0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.00000161801C4000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.0000016180158000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org |
Source: Pnihosiyvr.exe, 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CF85000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D298BAB000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80380000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.0000018357ADC000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.000001618010A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: MSBuild.exe, 0000000D.00000002.3229739212.0000016180158000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/156.146.36.197 |
Source: MSBuild.exe, 0000000C.00000002.3064626577.0000018357ADC000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.000001618010A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/156.146.36.197p |
Source: Pnihosiyvr.exe, 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2519177655.000002592BEA1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000C.00000002.3064626577.00000183579D1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 0000000D.00000002.3229739212.0000016180001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://scratchdreams.tk |
Source: Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CC78000.00000004.00000800.00020000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, Pnihosiyvr.exe, 00000000.00000002.2326053740.000001A32CFB1000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2769148817.000001D298BD0000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80380000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 0000000B.00000002.2853021181.0000020A80078000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: Pnihosiyvr.exe, 00000000.00000002.2332061251.000001A3453E0000.00000004.08000000.00040000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9986000.00000004.00000800.00020000.00000000.sdmp, sssssssssssssssss.exe, 00000008.00000002.2774836682.000001D2A9922000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000008.00000002.2769148817.000001D298BAB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0000000B.00000002.2853021181.0000020A80380000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000000.00000002.2326053740.000001A32CF85000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: Pnihosiyvr.exe PID: 6180, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: Pnihosiyvr.exe PID: 6180, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: MSBuild.exe PID: 2128, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: MSBuild.exe PID: 2128, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: sssssssssssssssss.exe PID: 6136, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: sssssssssssssssss.exe PID: 6136, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: sssssssssssssssss.exe PID: 2608, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: sssssssssssssssss.exe PID: 2608, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: version.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasman.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rtutils.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winhttp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: schannel.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: version.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasman.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rtutils.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winhttp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: schannel.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\choice.exe |
Section loaded: version.dll |
|
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 3.2.MSBuild.exe.140000000.0.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 11.2.sssssssssssssssss.exe.20a90de1538.2.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Pnihosiyvr.exe.1a33d992d00.5.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 8.2.sssssssssssssssss.exe.1d2a95d0d00.4.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 8.2.sssssssssssssssss.exe.1d2a95824c8.13.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Pnihosiyvr.exe.1a33d91ac90.8.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Pnihosiyvr.exe.1a33d942cc8.6.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000008.00000002.2781011462.000001D2B1430000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000008.00000002.2769148817.000001D298BAB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.2332481252.000001A34568A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000B.00000002.2862679952.0000020A90DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000008.00000002.2774836682.000001D2A9582000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0000000B.00000002.2853021181.0000020A80380000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000003.00000002.2517166281.0000000140002000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000000.00000002.2326053740.000001A32CF85000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.2327536841.000001A33D91A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: Pnihosiyvr.exe PID: 6180, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: Pnihosiyvr.exe PID: 6180, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: MSBuild.exe PID: 2128, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: MSBuild.exe PID: 2128, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: sssssssssssssssss.exe PID: 6136, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: sssssssssssssssss.exe PID: 6136, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: sssssssssssssssss.exe PID: 2608, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: sssssssssssssssss.exe PID: 2608, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 600000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599451 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599343 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599016 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598891 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598766 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598656 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598213 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598094 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597984 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597875 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597765 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597656 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597218 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597109 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596453 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596344 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596124 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595837 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595719 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595609 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594251 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594015 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593906 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593797 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593687 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593577 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593468 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593359 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593245 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 600000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599875 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599765 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599651 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599215 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599109 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598453 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598344 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598015 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597906 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597797 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597687 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597578 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597468 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597359 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597250 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597140 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597031 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596922 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596812 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596703 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596594 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596484 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596375 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596265 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596156 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596047 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595937 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595828 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595718 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595609 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595499 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595390 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595281 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595171 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595062 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594953 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594843 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594734 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594625 |
|
Source: C:\Users\user\Desktop\Pnihosiyvr.exe TID: 6524 |
Thread sleep time: -30000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Pnihosiyvr.exe TID: 4112 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe TID: 3536 |
Thread sleep time: -30000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe TID: 5504 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe TID: 6300 |
Thread sleep time: -30000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe TID: 5840 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep count: 32 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -29514790517935264s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -600000s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599890s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6324 |
Thread sleep count: 1631 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599781s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6324 |
Thread sleep count: 8217 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599672s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599562s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599451s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599343s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599234s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599125s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -599016s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598891s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598766s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598656s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598547s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598437s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598328s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598213s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -598094s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597984s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597875s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597765s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597656s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597547s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597437s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597328s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597218s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597109s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -597000s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596890s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596781s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596672s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596562s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596453s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596344s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596234s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -596124s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -595837s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -595719s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -595609s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -594251s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -594125s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -594015s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593906s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593797s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593687s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593577s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593468s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593359s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593245s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 6308 |
Thread sleep time: -593125s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep count: 31 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -28592453314249787s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -600000s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599875s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 4304 |
Thread sleep count: 1396 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 4304 |
Thread sleep count: 8462 > 30 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599765s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599651s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599547s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599437s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599328s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599215s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599109s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -599000s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598890s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598781s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598672s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598562s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598453s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598344s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598234s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598125s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -598015s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597906s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597797s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597687s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597578s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597468s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597359s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597250s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597140s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -597031s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596922s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596812s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596703s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596594s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596484s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596375s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596265s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596156s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -596047s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595937s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595828s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595718s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595609s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595499s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595390s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595281s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595171s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -595062s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -594953s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -594843s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -594734s >= -30000s |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe TID: 5352 |
Thread sleep time: -594625s >= -30000s |
|
Source: C:\Users\user\Desktop\Pnihosiyvr.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\sssssssssssssssss.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 600000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599451 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599343 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599016 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598891 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598766 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598656 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598213 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598094 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597984 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597875 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597765 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597656 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597218 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597109 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596453 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596344 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596124 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595837 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595719 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595609 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594251 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594015 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593906 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593797 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593687 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593577 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593468 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593359 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593245 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 593125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 600000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599875 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599765 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599651 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599547 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599437 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599328 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599215 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599109 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 599000 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598890 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598781 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598672 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598562 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598453 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598344 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598234 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598125 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 598015 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597906 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597797 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597687 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597578 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597468 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597359 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597250 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597140 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 597031 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596922 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596812 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596703 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596594 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596484 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596375 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596265 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596156 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 596047 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595937 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595828 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595718 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595609 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595499 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595390 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595281 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595171 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 595062 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594953 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594843 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594734 |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
Thread delayed: delay time: 594625 |
|