Source: C:\Users\Public\Documents\s1.dll |
Joe Sandbox ML: detected |
Source: werkernel.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2650 |
0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA1800 |
0_2_00007FF74DCA1800 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB02D8 |
0_2_00007FF74DCB02D8 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAB298 |
0_2_00007FF74DCAB298 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCABA68 |
0_2_00007FF74DCABA68 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB5E90 |
0_2_00007FF74DCB5E90 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAAE90 |
0_2_00007FF74DCAAE90 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB0DEC |
0_2_00007FF74DCB0DEC |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB21E0 |
0_2_00007FF74DCB21E0 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCABE00 |
0_2_00007FF74DCABE00 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAE14C |
0_2_00007FF74DCAE14C |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2D40 |
0_2_00007FF74DCA2D40 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAC8C8 |
0_2_00007FF74DCAC8C8 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAC490 |
0_2_00007FF74DCAC490 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAB094 |
0_2_00007FF74DCAB094 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCBAC18 |
0_2_00007FF74DCBAC18 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB076C |
0_2_00007FF74DCB076C |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCB632C |
0_2_00007FF74DCB632C |
Source: classification engine |
Classification label: mal56.winEXE@19/1@0/0 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, |
0_2_00007FF74DCA36B0 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7584:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7648:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7700:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7484:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7528:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7292:120:WilError_03 |
Source: werkernel.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: unknown |
Process created: C:\Users\user\Desktop\werkernel.exe "C:\Users\user\Desktop\werkernel.exe" |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Users\user\Desktop\werkernel.exe C:\Users\user\Desktop\werkernel.exe |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Users\user\Desktop\werkernel.exe C:\Users\user\Desktop\werkernel.exe |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: werkernel.exe |
Static PE information: Image base 0x140000000 > 0x60000000 |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: werkernel.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: werkernel.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: werkernel.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: werkernel.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: werkernel.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: werkernel.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: werkernel.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, |
0_2_00007FF74DCA2650 |
Source: werkernel.exe |
Static PE information: section name: _RDATA |
Source: s1.dll.0.dr |
Static PE information: section name: _RDATA |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, |
0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, |
0_2_00007FF74DCA36B0 |
Source: C:\Users\user\Desktop\werkernel.exe |
Evasive API call chain: GetModuleFileName,DecisionNodes,Sleep |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA10A0 GetSystemInfo,VirtualQuery,VirtualQuery,VirtualAlloc,VirtualAlloc, |
0_2_00007FF74DCA10A0 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAEA30 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FF74DCAEA30 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, |
0_2_00007FF74DCA36B0 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, |
0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCAEA30 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FF74DCAEA30 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA4D9C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FF74DCA4D9C |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA4938 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_00007FF74DCA4938 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA4F48 SetUnhandledExceptionFilter, |
0_2_00007FF74DCA4F48 |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, |
0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe |
Code function: 0_2_00007FF74DCA4FC0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, |
0_2_00007FF74DCA4FC0 |