Click to jump to signature section
Source: werkernel.exe | ReversingLabs: Detection: 60% |
Source: C:\Users\Public\Documents\s1.dll | Joe Sandbox ML: detected |
Source: werkernel.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2650 | 0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA1800 | 0_2_00007FF74DCA1800 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB02D8 | 0_2_00007FF74DCB02D8 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAB298 | 0_2_00007FF74DCAB298 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCABA68 | 0_2_00007FF74DCABA68 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB5E90 | 0_2_00007FF74DCB5E90 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAAE90 | 0_2_00007FF74DCAAE90 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB0DEC | 0_2_00007FF74DCB0DEC |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB21E0 | 0_2_00007FF74DCB21E0 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCABE00 | 0_2_00007FF74DCABE00 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAE14C | 0_2_00007FF74DCAE14C |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2D40 | 0_2_00007FF74DCA2D40 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAC8C8 | 0_2_00007FF74DCAC8C8 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAC490 | 0_2_00007FF74DCAC490 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAB094 | 0_2_00007FF74DCAB094 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCBAC18 | 0_2_00007FF74DCBAC18 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB076C | 0_2_00007FF74DCB076C |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCB632C | 0_2_00007FF74DCB632C |
Source: classification engine | Classification label: mal56.winEXE@19/1@0/0 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, | 0_2_00007FF74DCA36B0 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7584:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7648:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7700:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7484:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7528:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7292:120:WilError_03 |
Source: werkernel.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: werkernel.exe | ReversingLabs: Detection: 60% |
Source: unknown | Process created: C:\Users\user\Desktop\werkernel.exe "C:\Users\user\Desktop\werkernel.exe" | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Users\user\Desktop\werkernel.exe C:\Users\user\Desktop\werkernel.exe | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Users\user\Desktop\werkernel.exe C:\Users\user\Desktop\werkernel.exe | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: winbrand.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: winbrand.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: werkernel.exe | Static PE information: Image base 0x140000000 > 0x60000000 |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: werkernel.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: werkernel.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: werkernel.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: werkernel.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: werkernel.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: werkernel.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: werkernel.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, | 0_2_00007FF74DCA2650 |
Source: werkernel.exe | Static PE information: section name: _RDATA |
Source: s1.dll.0.dr | Static PE information: section name: _RDATA |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, | 0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, | 0_2_00007FF74DCA36B0 |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA10A0 GetSystemInfo,VirtualQuery,VirtualQuery,VirtualAlloc,VirtualAlloc, | 0_2_00007FF74DCA10A0 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAEA30 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_00007FF74DCAEA30 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA36B0 CreateToolhelp32Snapshot,Thread32First,GetCurrentProcessId,GetCurrentThreadId,HeapAlloc,HeapReAlloc,Thread32Next,GetLastError,HeapFree,FindCloseChangeNotification, | 0_2_00007FF74DCA36B0 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, | 0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCAEA30 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_00007FF74DCAEA30 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA4D9C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_00007FF74DCA4D9C |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA4938 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 0_2_00007FF74DCA4938 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA4F48 SetUnhandledExceptionFilter, | 0_2_00007FF74DCA4F48 |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA2650 GetModuleHandleW,Sleep,HeapCreate,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,LoadLibraryW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,PathFileExistsA,PathFileExistsA,SleepEx,PathFileExistsA,CreateProcessA,PathFileExistsA,Sleep,ShellExecuteA,Sleep,PathFileExistsA, | 0_2_00007FF74DCA2650 |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\werkernel.exe | Code function: 0_2_00007FF74DCA4FC0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, | 0_2_00007FF74DCA4FC0 |