Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
16770075581.zip

Overview

General Information

Sample name:16770075581.zip
Analysis ID:1431511
MD5:0531a38f0874c57a473f615b1608609e
SHA1:2f70912946681142433683d58e0db1d3eba27e75
SHA256:6b796b7bd4247c7c56976940fae8292cb633a1924ea940c5cd973fe8db4fb1ae
Infos:

Detection

AgentTesla, PureLog Stealer
Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Yara detected AgentTesla
Yara detected PureLog Stealer
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Outbound SMTP Connections
Uses SMTP (mail sending)
Yara detected Credential Stealer

Classification

  • System is w10x64_ra
  • rundll32.exe (PID: 6900 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe (PID: 1592 cmdline: "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe" MD5: 1B1A6E8EA0B16F3611864E07458C7358)
    • a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe (PID: 2512 cmdline: "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe" MD5: 1B1A6E8EA0B16F3611864E07458C7358)
  • a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe (PID: 3680 cmdline: "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe" MD5: 1B1A6E8EA0B16F3611864E07458C7358)
    • a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe (PID: 4116 cmdline: "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe" MD5: 1B1A6E8EA0B16F3611864E07458C7358)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Agent Tesla, AgentTeslaA .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
  • SWEED
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
SourceRuleDescriptionAuthorStrings
0000000F.00000002.1854317165.0000000006320000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    0000000F.00000002.1855204335.0000000006D71000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      0000000F.00000002.1841875926.0000000004A6C000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        0000000F.00000002.1841875926.0000000004A6C000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          0000000F.00000002.1855204335.0000000006C81000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            Click to see the 25 entries
            Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 148.251.133.229, DestinationIsIpv6: false, DestinationPort: 587, EventID: 3, Image: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe, Initiated: true, ProcessId: 2512, Protocol: tcp, SourceIp: 192.168.2.17, SourceIsIpv6: false, SourcePort: 49725
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: confirmyourinfo.comVirustotal: Detection: 10%Perma Link
            Source: unknownHTTPS traffic detected: 142.202.136.11:443 -> 192.168.2.17:49723 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.17:49724 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.202.136.11:443 -> 192.168.2.17:49726 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.17:49729 version: TLS 1.2
            Source: global trafficTCP traffic: 192.168.2.17:49725 -> 148.251.133.229:587
            Source: unknownDNS query: name: api.ipify.org
            Source: unknownDNS query: name: api.ipify.org
            Source: unknownDNS query: name: api.ipify.org
            Source: global trafficTCP traffic: 192.168.2.17:49725 -> 148.251.133.229:587
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficDNS traffic detected: DNS query: confirmyourinfo.com
            Source: global trafficDNS traffic detected: DNS query: api.ipify.org
            Source: global trafficDNS traffic detected: DNS query: mail.seatech.co.ke
            Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
            Source: unknownHTTPS traffic detected: 142.202.136.11:443 -> 192.168.2.17:49723 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.17:49724 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.202.136.11:443 -> 192.168.2.17:49726 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.17:49729 version: TLS 1.2
            Source: classification engineClassification label: mal88.troj.spyw.evad.winZIP@7/0@3/19
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMutant created: NULL
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
            Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
            Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
            Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
            Source: unknownProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: unknownProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mscoree.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: apphelp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wldp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: profapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasapi32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasman.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rtutils.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mswsock.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winhttp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winnsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasadhlp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: fwpuclnt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: secur32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: sspicli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: schannel.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mskeyprotect.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ntasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncrypt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncryptsslp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: msasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: gpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: amsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: userenv.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mscoree.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wldp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: profapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wbemcomn.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: amsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: userenv.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: sspicli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasapi32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasman.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rtutils.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mswsock.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winhttp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winnsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasadhlp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: fwpuclnt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: secur32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: schannel.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mskeyprotect.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ntasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncrypt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncryptsslp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: msasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: gpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vaultcli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mscoree.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wldp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: profapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasapi32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasman.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rtutils.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mswsock.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winhttp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winnsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasadhlp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: fwpuclnt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: secur32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: sspicli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: schannel.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mskeyprotect.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ntasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncrypt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncryptsslp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: msasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: gpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: amsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: userenv.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mscoree.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wldp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: profapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wbemcomn.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: amsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: userenv.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: sspicli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasapi32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasman.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rtutils.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mswsock.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winhttp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: winnsi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: rasadhlp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: fwpuclnt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: secur32.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: schannel.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: mskeyprotect.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ntasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncrypt.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: ncryptsslp.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: msasn1.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: gpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: vaultcli.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeSection loaded: dpapi.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\Profiles

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 0000000F.00000002.1854317165.0000000006320000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1855204335.0000000006D71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1855204335.0000000006C81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1839140970.0000000002E39000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2060893027.0000000007431000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2060893027.00000000074D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2040197303.00000000036E7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
            Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2AE0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2C10000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 4C10000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 6C80000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 6470000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2B90000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2D60000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2BB0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 1A70000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 34C0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 33D0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 73E0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 6BD0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: E20000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2810000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: 2620000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWindow / User API: threadDelayed 9862
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWindow / User API: threadDelayed 7780
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 4144Thread sleep time: -30000s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1740Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -5534023222112862s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -100000s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99888s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6196Thread sleep count: 9862 > 30
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99776s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99664s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99552s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99424s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99281s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99169s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -99057s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98945s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98833s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98705s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98577s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98465s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98353s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98241s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98130s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -98002s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97874s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97763s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97651s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97539s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97427s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97299s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97171s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -97060s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96948s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96836s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96724s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96596s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96468s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96356s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96244s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96132s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -96020s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95892s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95764s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95652s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95540s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95428s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95300s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95173s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -95029s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94917s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94805s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94694s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94582s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94455s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94327s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6204Thread sleep time: -94216s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 6564Thread sleep time: -30000s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 3964Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -1844674407370954s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -200000s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99872s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 2028Thread sleep count: 7780 > 30
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99760s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99648s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99536s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99409s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99282s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99170s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99058s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98946s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98834s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98706s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98562s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98450s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98338s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98226s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98114s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97986s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97858s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97746s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97635s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97524s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97412s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97284s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97156s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97044s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -96932s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -96820s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -96708s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -96580s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -96452s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99888s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99776s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99664s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99553s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99426s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99314s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99186s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -99074s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98962s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98850s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98738s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98626s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98498s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98386s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98274s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98162s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -98034s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe TID: 1044Thread sleep time: -97922s >= -30000s
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 100000
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99888
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99776
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99664
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99552
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99424
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99281
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99169
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99057
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98945
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98833
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98705
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98577
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98465
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98353
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98241
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98130
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98002
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97874
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97763
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97651
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97539
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97427
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97299
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97171
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97060
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96948
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96836
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96724
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96596
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96468
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96356
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96244
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96132
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96020
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95892
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95764
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95652
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95540
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95428
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95300
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95173
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 95029
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94917
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94805
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94694
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94582
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94455
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94327
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 94216
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 100000
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99872
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99760
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99648
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99536
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99409
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99282
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99170
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99058
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98946
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98834
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98706
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98562
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98450
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98338
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98226
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98114
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97986
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97858
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97746
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97635
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97524
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97412
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97284
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97156
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97044
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96932
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96820
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96708
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96580
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 96452
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99888
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99776
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99664
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99553
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99426
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99314
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99186
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 99074
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98962
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98850
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98738
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98626
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98498
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98386
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98274
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98162
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 98034
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeThread delayed: delay time: 97922
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess information queried: ProcessInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeMemory allocated: page read and write | page guard
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeProcess created: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe "C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe"
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exe VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 0000000F.00000002.1841875926.0000000004A6C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1855204335.0000000006C81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1839140970.0000000002F2B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DDB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2037601987.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DE5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2040197303.00000000037D9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DB1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.00000000028A0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.0000000002895000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.000000000288B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.0000000002861000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1841875926.00000000046FC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1849874481.0000000005E10000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1841875926.0000000003FF9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\8h0a78bs.default-release\cookies.sqlite
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\FTP Navigator\Ftplist.txt
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities
            Source: C:\Users\user\Desktop\a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
            Source: Yara matchFile source: 0000000F.00000002.1841875926.0000000004A6C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1855204335.0000000006C81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1839140970.0000000002F2B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2037601987.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2040197303.00000000037D9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DB1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.0000000002861000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 0000000F.00000002.1841875926.0000000004A6C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1855204335.0000000006C81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1839140970.0000000002F2B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DDB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2037601987.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DE5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000013.00000002.2040197303.00000000037D9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.2041946472.0000000002DB1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.00000000028A0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.0000000002895000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.000000000288B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000014.00000002.2439032914.0000000002861000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1841875926.00000000046FC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1849874481.0000000005E10000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.1841875926.0000000003FF9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts121
            Windows Management Instrumentation
            1
            DLL Side-Loading
            11
            Process Injection
            1
            Disable or Modify Tools
            2
            OS Credential Dumping
            11
            Security Software Discovery
            Remote Services1
            Email Collection
            2
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            141
            Virtualization/Sandbox Evasion
            1
            Credentials in Registry
            1
            Query Registry
            Remote Desktop Protocol2
            Data from Local System
            1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
            Process Injection
            Security Account Manager1
            Process Discovery
            SMB/Windows Admin SharesData from Network Shared Drive1
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Rundll32
            NTDS141
            Virtualization/Sandbox Evasion
            Distributed Component Object ModelInput Capture12
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            DLL Side-Loading
            LSA Secrets1
            Application Window Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
            System Network Configuration Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync1
            File and Directory Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem24
            System Information Discovery
            Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            confirmyourinfo.com11%VirustotalBrowse
            seatech.co.ke0%VirustotalBrowse
            mail.seatech.co.ke0%VirustotalBrowse
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            seatech.co.ke
            148.251.133.229
            truefalseunknown
            confirmyourinfo.com
            142.202.136.11
            truetrueunknown
            api.ipify.org
            104.26.12.205
            truefalse
              high
              mail.seatech.co.ke
              unknown
              unknownfalseunknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              104.26.12.205
              api.ipify.orgUnited States
              13335CLOUDFLARENETUSfalse
              142.202.136.11
              confirmyourinfo.comReserved
              52284PanamaservercomPAtrue
              148.251.133.229
              seatech.co.keGermany
              24940HETZNER-ASDEfalse
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1431511
              Start date and time:2024-04-25 11:17:54 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:21
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              Analysis Mode:stream
              Analysis stop reason:Timeout
              Sample name:16770075581.zip
              Detection:MAL
              Classification:mal88.troj.spyw.evad.winZIP@7/0@3/19
              Cookbook Comments:
              • Found application associated with file extension: .zip
              • Exclude process from analysis (whitelisted): dllhost.exe
              • Excluded IPs from analysis (whitelisted): 40.126.28.20, 40.126.28.19, 40.126.28.11, 40.126.28.21, 40.126.28.18, 40.126.7.32, 40.126.28.13, 40.126.28.14
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              No created / dropped files found
              File type:Zip archive data, at least v2.0 to extract, compression method=deflate
              Entropy (8bit):7.995256499309422
              TrID:
              • ZIP compressed archive (8000/1) 99.91%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.09%
              File name:16770075581.zip
              File size:44'172 bytes
              MD5:0531a38f0874c57a473f615b1608609e
              SHA1:2f70912946681142433683d58e0db1d3eba27e75
              SHA256:6b796b7bd4247c7c56976940fae8292cb633a1924ea940c5cd973fe8db4fb1ae
              SHA512:7ff3753d490ceed05fb07d7a3f29df7c8019305bee50a48921bb9540b55bced0709d14b6c9fc424a12986fd766f7f338a963b239cea55b7ca1080f7176ad444c
              SSDEEP:768:w2ogmTjbrboSX2dmNKmyN1I+o2eHuGxV9luI7OejSe7MvMdhchC+bAgHNLp6c:ZogecSaF9I+odPV9l/7OKQohchrHRsc
              TLSH:BA1302D689270490C3BEE023394866A1532EDC4DA6CFDC3510E96BAD169FF5F2B50ED8
              File Content Preview:PK........................@...a0611257eaad7ff0528e4305d35a8929fc4cf268b0d7201e417ce0458040a9fa.#..N.J...*...........8..x.Cgp..[6PIv.... L?.#...m.;=.....9.U....N...!...H.7..p...o5N..?L...!<.r..L...p /)_.....ac.r.....|x.E..X.d}0..:vD]. ..2y..6.w.+b..58'R...
              Icon Hash:1c1c1e4e4ececedc