Windows Analysis Report
SecuriteInfo.com.FileRepPup.14974.19067.exe

Overview

General Information

Sample name: SecuriteInfo.com.FileRepPup.14974.19067.exe
Analysis ID: 1431659
MD5: c27c3107bb20803c3f5d8eab7258bb48
SHA1: 9e8384e96c6542eaf091cec68c351b8bde8d1b96
SHA256: 42e35e59355e78dc581115d24babd4424422efacfdb6710395c27e84243959df
Tags: exe
Infos:

Detection

Score: 32
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Drops password protected ZIP file
Uses schtasks.exe or at.exe to add and modify task schedules
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Detected potential crypto function
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Is looking for software installed on the system
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe (copy) Virustotal: Detection: 14% Perma Link
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe (copy) Virustotal: Detection: 8% Perma Link
Source: C:\Program Files (x86)\Wise\Wise Care 365\is-HBE50.tmp Virustotal: Detection: 14% Perma Link
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe ReversingLabs: Detection: 15%
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Virustotal: Detection: 12% Perma Link
Source: https://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fwisecleanersoft&send=false&layout=button_count&width=110&show_faces=false&font&colorscheme=light&action=like&height=21 HTTP Parser: No favicon
Source: https://platform.twitter.com/widgets/widget_iframe.2f70fb173b9000da126c79afe2098f02.html?origin=https%3A%2F%2Fwww.wisecleaner.com HTTP Parser: No favicon
Source: https://www.youtube.com/subscribe_embed?usegapi=1&channel=wisecleanervideo&layout=default&count=default&origin=https%3A%2F%2Fwww.wisecleaner.com&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__#_methods=onPlusOne%2C_ready%2C_close%2C_open%2C_resizeMe%2C_renderstart%2Concircled%2Cdrefresh%2Cerefresh%2Conload&id=I0_1714051839396&_gfid=I0_1714051839396&parent=https%3A%2F%2Fwww.wisecleaner.com&pfname=&rpctoken=22571271 HTTP Parser: No favicon
Source: https://platform.twitter.com/widgets/follow_button.2f70fb173b9000da126c79afe2098f02.en.html#dnt=false&id=twitter-widget-0&lang=en&screen_name=WiseCleaner&show_count=false&show_screen_name=false&size=m&time=1714051841571 HTTP Parser: No favicon
Source: https://accounts.google.com/o/oauth2/postmessageRelay?parent=https%3A%2F%2Fwww.wisecleaner.com&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__#rpctoken=1872338475&forcesecure=1 HTTP Parser: No favicon
Source: https://www.youtube.com/subscribe_embed?action_card=1&channelid=UCXLbiumrDzPSJikI9BIZjrw&usegapi=1&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__#id=I0_1714051842536&_gfid=I0_1714051842536&parent=https%3A%2F%2Fwww.wisecleaner.com&pfname=&rpctoken=24310883 HTTP Parser: No favicon
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Users\user\AppData\Local\Temp\is-1Q5HG.tmp\license.txt Jump to behavior
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49911 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49909 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49910 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49914 version: TLS 1.2
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: G:\workspace\windows\NewToolsProject\SQLite3Encrypt\Release\SQLite3Encrypt.pdb source: WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: G:\workspace\windows\WiseCare365_V4\Bootlancher\Release\Bootlauncher.pdb source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: global traffic HTTP traffic detected: GET /wisecleaner_feedback/index.php?to=fetch-unread-message&guid={00280FF0-8444-4589-ABB1-07A5B9247E0B} HTTP/1.1Accept-Charset: utf-8Host: www.wisecleaner.netCache-Control: no-cache
Source: Joe Sandbox View IP Address: 104.244.42.72 104.244.42.72
Source: Joe Sandbox View IP Address: 104.244.42.136 104.244.42.136
Source: Joe Sandbox View IP Address: 104.244.42.8 104.244.42.8
Source: Joe Sandbox View IP Address: 192.229.163.25 192.229.163.25
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: Joe Sandbox View JA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 52.6.97.148
Source: unknown TCP traffic detected without corresponding DNS query: 23.40.205.34
Source: unknown TCP traffic detected without corresponding DNS query: 23.40.205.34
Source: unknown TCP traffic detected without corresponding DNS query: 34.202.12.236
Source: unknown TCP traffic detected without corresponding DNS query: 34.202.12.236
Source: unknown TCP traffic detected without corresponding DNS query: 13.32.230.50
Source: unknown TCP traffic detected without corresponding DNS query: 13.32.230.50
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknown TCP traffic detected without corresponding DNS query: 13.85.23.86
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=PwDlxXseu3VEHbh&MD=lcm7x2Bz HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /thanks-for-choosing-WiseCare365.html HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/css/reset.css HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/css/layout.css?v=1.24 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/css/layout-mobile.css?v=1.08 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/css/roboto.css?v=1.07 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/page/product/update/update.css HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/page/product/thanks-download/thanks-download.css HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fwisecleanersoft&send=false&layout=button_count&width=110&show_faces=false&font&colorscheme=light&action=like&height=21 HTTP/1.1Host: www.facebook.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/svg/logo/pdf_logo.svg HTTP/1.1Host: pdf.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_america.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_1f2238_12.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_french.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_germany.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_japan.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_russia.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3iEpO4/yv/l/en_US/tQNtwFBP_EQ.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.facebook.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yD/r/FEppCFCt76d.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/font/roboto/v29/KFOmCnqEu92Fr1Mu4mxKKTU1Kg.woff2 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://www.wisecleaner.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.wisecleaner.com/static/css/roboto.css?v=1.07Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/font/roboto/v29/KFOmCnqEu92Fr1Mu5mxKKTU1Kvnz.woff2 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://www.wisecleaner.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.wisecleaner.com/static/css/roboto.css?v=1.07Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/update/icon.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/card.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/logo/logo.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/clean.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/norton.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/bbb.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/macfee.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/sign.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/day_50.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/drw-win-icon_77.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/page/product/update/update.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_french.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_1f2238_12.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_germany.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/svg/logo/pdf_logo.svg HTTP/1.1Host: pdf.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_japan.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_russia.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_america.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_1f2238_18.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_china.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_wdf.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_365.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_wfh.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/special_offer_box.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yD/r/FEppCFCt76d.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3iEpO4/yv/l/en_US/tQNtwFBP_EQ.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/clean.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/logo/logo.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/update/icon.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/card.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/norton.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/bbb.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wfh-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wrc-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/index-menu.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/static/css/layout.css?v=1.24Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wdc-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wu-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/was-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/macfee.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/sign.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/drw-win-icon_77.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/day_50.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_1f2238_18.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_china.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/whk-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/softpedia-wfh.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/softonic_w365_4.5stars.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/si-award-epick5.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_twitter.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_facebook.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_wdf.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_wfh.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/thanks_box_365.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/thanks-for-choosing/special_offer_box.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_youtube.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_wordpress.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_newsletter.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_eff0f2_12.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/page/product/choose-product-discount/choose-product-discount.js HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/page/layout/layout.js?v=1.80 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/js/utils/utils.js?v=1.14 HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/js/common/sprint.min.js HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.wisecleaner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wfh-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wrc-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/index-menu.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wdc-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/wu-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/was-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/product/products_icon/whk-60.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/softpedia-wfh.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/softonic_w365_4.5stars.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_facebook.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_twitter.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/awards/si-award-epick5.png HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /js/platform.js HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /widgets.js HTTP/1.1Host: platform.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cse/static/element/8435450f13508ca1/default+en.css HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cse/static/style/look/v4/default.css HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cse/static/element/8435450f13508ca1/cse_element__en.js?usqp=CAI%3D HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_youtube.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_follow_wordpress.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/common/icon_newsletter.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/img/icon/icon_arrow_eff0f2_12.svg HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.wisecleaner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.JisoxTPHVRs.O/m=ytsubscribe/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg/cb=gapi.loaded_0?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.JisoxTPHVRs.O/m=auth/exm=ytsubscribe/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg/cb=gapi.loaded_1?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /subscribe_embed?usegapi=1&channel=wisecleanervideo&layout=default&count=default&origin=https%3A%2F%2Fwww.wisecleaner.com&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__ HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /widgets/widget_iframe.2f70fb173b9000da126c79afe2098f02.html?origin=https%3A%2F%2Fwww.wisecleaner.com HTTP/1.1Host: platform.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/css/www-subscribe-embed_split_v0.css HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.youtube.com/subscribe_embed?usegapi=1&channel=wisecleanervideo&layout=default&count=default&origin=https%3A%2F%2Fwww.wisecleaner.com&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/js/www-subscribe-embed_v0.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/subscribe_embed?usegapi=1&channel=wisecleanervideo&layout=default&count=default&origin=https%3A%2F%2Fwww.wisecleaner.com&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /settings?session_id=23573a4b92be966386dd3bcaa06c1e011847d690 HTTP/1.1Host: syndication.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://platform.twitter.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://platform.twitter.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/img/subscribe_button_branded_lozenge.png HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.youtube.com/s/subscriptions/subscribe_embed/css/www-subscribe-embed_split_v0.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /js/rpc:shindig_random.js?onload=init HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.JisoxTPHVRs.O/m=gapi_iframes,gapi_iframes_style_common/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg/cb=gapi.loaded_0 HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /js/button.856debeac157d9669cf51e73a08fbc93.js HTTP/1.1Host: platform.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /settings?session_id=23573a4b92be966386dd3bcaa06c1e011847d690 HTTP/1.1Host: syndication.twitter.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/img/subscribe_button_branded_lozenge.png HTTP/1.1Host: www.youtube.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.JisoxTPHVRs.O/m=rpc,shindig_random/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg/cb=gapi.loaded_0?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /i/jot/embeds?l=%7B%22widget_origin%22%3A%22https%3A%2F%2Fwww.wisecleaner.com%2Fthanks-for-choosing-WiseCare365.html%22%2C%22widget_frame%22%3Afalse%2C%22language%22%3A%22en%22%2C%22message%22%3A%22m%3Awithcount%3A%22%2C%22_category_%22%3A%22tfw_client_event%22%2C%22triggered_on%22%3A1714051841572%2C%22dnt%22%3Afalse%2C%22client_version%22%3A%222615f7e52b7e0%3A1702314776716%22%2C%22format_version%22%3A1%2C%22event_namespace%22%3A%7B%22client%22%3A%22tfw%22%2C%22page%22%3A%22button%22%2C%22section%22%3A%22follow%22%2C%22action%22%3A%22impression%22%7D%7D&session_id=23573a4b92be966386dd3bcaa06c1e011847d690 HTTP/1.1Host: syndication.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /widgets/follow_button.2f70fb173b9000da126c79afe2098f02.en.html HTTP/1.1Host: platform.twitter.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.JisoxTPHVRs.O/m=gapi_iframes_style_bubble/exm=auth,ytsubscribe/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg/cb=gapi.loaded_2?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /j/collect?t=dc&aip=1&_r=3&v=1&_v=j101&tid=UA-17835040-1&cid=1842655186.1714051839&jid=1016391291&gjid=194722105&_gid=672239341.1714051841&_u=YADAAUAAAAAAACAAI~&z=1130479592 HTTP/1.1Host: stats.g.doubleclick.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /i/jot/embeds?l=%7B%22widget_origin%22%3A%22https%3A%2F%2Fwww.wisecleaner.com%2Fthanks-for-choosing-WiseCare365.html%22%2C%22widget_frame%22%3Afalse%2C%22language%22%3A%22en%22%2C%22message%22%3A%22m%3Awithcount%3A%22%2C%22_category_%22%3A%22tfw_client_event%22%2C%22triggered_on%22%3A1714051841572%2C%22dnt%22%3Afalse%2C%22client_version%22%3A%222615f7e52b7e0%3A1702314776716%22%2C%22format_version%22%3A1%2C%22event_namespace%22%3A%7B%22client%22%3A%22tfw%22%2C%22page%22%3A%22button%22%2C%22section%22%3A%22follow%22%2C%22action%22%3A%22impression%22%7D%7D&session_id=23573a4b92be966386dd3bcaa06c1e011847d690 HTTP/1.1Host: syndication.twitter.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /subscribe_embed?action_card=1&channelid=UCXLbiumrDzPSJikI9BIZjrw&usegapi=1&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__ HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/css/www-subscribe-embed-card_v0.css HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.youtube.com/subscribe_embed?action_card=1&channelid=UCXLbiumrDzPSJikI9BIZjrw&usegapi=1&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /s/subscriptions/subscribe_embed/js/www-subscribe-embed-card_v0.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/subscribe_embed?action_card=1&channelid=UCXLbiumrDzPSJikI9BIZjrw&usegapi=1&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.lb.en.JisoxTPHVRs.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo9VOmUKkb8FAwL65OiDUU4etqWcRg%2Fm%3D__features__Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=YnkeQfygHdM; VISITOR_INFO1_LIVE=2rbnv3xY9ig; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgJg%3D%3D
Source: global traffic HTTP traffic detected: GET /messages/index.php?to=checknews&pid=3 HTTP/1.1Connection: Keep-AliveAccept-Charset: utf-8User-Agent: Embarcadero URI Client/1.0Host: info.wisecleaner.com
Source: global traffic HTTP traffic detected: GET /toolbox/toolsv6.ini HTTP/1.1Connection: Keep-AliveUser-Agent: Embarcadero URI Client/1.0Host: www.wisecleaner.com
Source: global traffic HTTP traffic detected: GET /software_update/getinfo_v6.php?p_id=31&s_build=636 HTTP/1.1Connection: Keep-AliveAccept-Charset: utf-8User-Agent: Embarcadero URI Client/1.0Host: www.wisecleaner.com
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=PwDlxXseu3VEHbh&MD=lcm7x2Bz HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQMDtATfnJO6JAXDQoHl8pAaJdhTQQU3QQJB6L1en1SUxKSle44gCUNplkCEG1SGHCH6CNNhWAA0ICPk1Y%3D HTTP/1.1Cache-Control: max-age = 86400Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Nov 2023 17:37:40 GMTIf-None-Match: "be34871fa05e0a45e7d6f78f5d8828db47b667ba"User-Agent: Microsoft-CryptoAPI/10.0Host: ocsps.ssl.com
Source: global traffic HTTP traffic detected: GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQg3SSkKA74hABkhmlBtJTz8w3hlAQU%2BWC71OPVNPa49QaAJadz20ZpqJ4CEEJLalPOx2YUHCpjsaUcQQQ%3D HTTP/1.1Cache-Control: max-age = 86400Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Nov 2023 17:37:47 GMTIf-None-Match: "4ea8ecb5e7b4c11f4c491caf6cee7ced5ec4c267"User-Agent: Microsoft-CryptoAPI/10.0Host: ocsps.ssl.com
Source: global traffic HTTP traffic detected: GET /info_group/index.php?to=getinfonew&pid=15 HTTP/1.1Connection: Keep-AliveAccept-Charset: utf-8User-Agent: Embarcadero URI Client/1.0Host: info.wisecleaner.com
Source: global traffic HTTP traffic detected: GET /info_group/images/2024/04/12/012055670.png HTTP/1.1Connection: Keep-AliveUser-Agent: Embarcadero URI Client/1.0Host: info.wisecleaner.com
Source: global traffic HTTP traffic detected: GET /wisecleaner_feedback/index.php?to=fetch-unread-message&guid={00280FF0-8444-4589-ABB1-07A5B9247E0B} HTTP/1.1Accept-Charset: utf-8Host: www.wisecleaner.netCache-Control: no-cache
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: Mhttps://www.facebook.com/sharer/sharer.php?u=wisecleaner.com/wisecare365.html equals www.facebook.com (Facebook)
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://twitter.com/share?original_referer=http://www.wisecleaner.com/&source=tweetbutton&text=Fast and easy to clean junk files and traces.&url=http://www.wisecleaner.com/&via=wisecleaner equals www.twitter.com (Twitter)
Source: global traffic DNS traffic detected: DNS query: www.wisecleaner.com
Source: global traffic DNS traffic detected: DNS query: www.facebook.com
Source: global traffic DNS traffic detected: DNS query: pdf.wisecleaner.com
Source: global traffic DNS traffic detected: DNS query: static.xx.fbcdn.net
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: cse.google.com
Source: global traffic DNS traffic detected: DNS query: platform.twitter.com
Source: global traffic DNS traffic detected: DNS query: apis.google.com
Source: global traffic DNS traffic detected: DNS query: www.adsensecustomsearchads.com
Source: global traffic DNS traffic detected: DNS query: www.youtube.com
Source: global traffic DNS traffic detected: DNS query: syndication.twitter.com
Source: global traffic DNS traffic detected: DNS query: stats.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: twitter.com
Source: global traffic DNS traffic detected: DNS query: www.wisecleaner.net
Source: global traffic DNS traffic detected: DNS query: info.wisecleaner.com
Source: unknown HTTP traffic detected: POST /j/collect?t=dc&aip=1&_r=3&v=1&_v=j101&tid=UA-17835040-1&cid=1842655186.1714051839&jid=1016391291&gjid=194722105&_gid=672239341.1714051841&_u=YADAAUAAAAAAACAAI~&z=1130479592 HTTP/1.1Host: stats.g.doubleclick.netConnection: keep-aliveContent-Length: 0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: text/plainAccept: */*Origin: https://www.wisecleaner.comX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.wisecleaner.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://cert.ssl.com/SSL.com-timeStamping-I-RSA-R1.cer0Q
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.cer0_
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1671935264.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2052358843.000000000461F000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2017922213.00000000054E0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1679146180.0000000003410000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://counter-strike.com.ua/
Source: WiseCare365.exe, 00000009.00000003.2724199825.000000000A781000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A77C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.micro
Source: svchost.exe, 0000000A.00000002.2937097262.000001A0D8000000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.ver)
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://crls.ssl.com/SSL.com-timeStamping-I-RSA-R1.crl0
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://crls.ssl.com/SSLcom-RootCA-EV-RSA-4096-R2.crl0
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.crl0
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://crls.ssl.com/ssl.com-rsa-RootCA.crl0
Source: WiseCare365.exe, 00000009.00000003.2015758565.00000000055D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://damnedovycestiny.webnode.cz/
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WASSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WDFSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WDRSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WFDSetup.exe
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WFDSetup.exe_
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WGBSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WJSSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WMOSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WPUSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/soft/WRMSetup.exe
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/AutoUpdate_6.0.3.593.zip
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/BootLauncher_6.0.3.593.zip
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/BootPack_6.0.3.593.zipsvg
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/BootTime_6.0.3.593.zipsvg
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/DManager_6.1.4.601.zip
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/DefragOptions_6.0.3.593.zip
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Arabic.lanA
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Azerbaijani(Latin).lanUU
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Bulgarian.lan.4153
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Catalan.lan2
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Chinese(Simplified).lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Chinese(Traditional).lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Croatian.lan98
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Czech.lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Danish.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Dutch(Belgium).lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Dutch(Nederlands).lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/English.lan2351
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Finnish.lan0773337a
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/French.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Georgian.lan.25891
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/German.lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Greek.lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Hebrew.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Hungarian.lanC20.8
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Indonesian.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Italian.lan931334
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Japanese.lan.6
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Korean.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Kurdish.lan51
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Lithuanian.lan2
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Nepali.lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Norwegian(Bokmal).lanb
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Norwegian(Nynorsk).lanUU
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Persian.lan.964558
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Polish.lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Portuguese(Portugal).lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Romanian.lantion
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Russian.lanA
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Serbian(Cyrillic).lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Slovak.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Slovenian.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Spanish(Spain).lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Swedish(Sweden).lan
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Thai.lanA
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Turkish.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005400000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Ukrainian.lan
Source: WiseCare365.exe, 00000009.00000002.2961151274.0000000005418000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Languages/Vietnamese.laneCare365
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/Rate_6.6.6.636.zip)
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/WJSLib_6.0.3.593.zipa
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003404000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/WiseBootBooster_6.5.2.624.zip
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/WiseCare365_6.6.6.636.zipm
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/WiseDefrag_6.0.3.593.zipp4L
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/WiseEraser_6.0.3.593.zipsoft
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/fileshredder_6.0.3.593.zipq4L
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/libeay32_6.0.3.593.zipH
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/sqlite3_6.0.3.593.zip
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/ssleay32_6.0.3.593.zipH
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://downloads.wisecleaner.com/update/care365_v6/tools/toolsv6.zip
Source: svchost.exe, 0000000A.00000002.2938109224.000001A0D80FB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acosgr5ufcefr7w7nv4v6k4ebdda_117.0.5938.132/117.0.5
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8218000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg
Source: svchost.exe, 0000000A.00000002.2937750277.000001A0D80CA000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2935036390.000001A0D3302000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000003.2598184419.000001A0D7EF2000.00000004.00000800.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2937232866.000001A0D8042000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2937232866.000001A0D802C000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2937500417.000001A0D8061000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/an2dmhqv5igncgwzelkqyugk5q_2024.4.19.0/go
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D824D000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe
Source: svchost.exe, 0000000A.00000002.2937500417.000001A0D808F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com:80
Source: svchost.exe, 0000000A.00000002.2937500417.000001A0D8061000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://edgedl.me.gvt1.com:80/edgedl/release2/chrome_component/an2dmhqv5igncgwzelkqyugk5q_2024.4.19.0
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8291000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A754000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000199D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://info.wisecleaner.com/
Source: WiseCare365.exe, 00000009.00000002.2940777387.000000000197C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.0000000001978000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2722553412.0000000001992000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.0000000001992000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.00000000033D2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://info.wisecleaner.com/info_group/images/2024/04/12/012055670.png
Source: WiseCare365.exe, 00000009.00000000.1965205495.0000000001368000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://info.wisecleaner.com/info_group/index.php?to=getinfonew&pid=15
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://info.wisecleaner.com/info_group/index.php?to=getinfonew&pid=15i
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A754000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://info.wisecleaner.com:80/info_group/images/2024/04/12/012055670.png
Source: WiseCare365.exe, 00000009.00000002.2937181357.00000000018B8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://info.wisecleaner.com:80/info_group/index.php?to=getinfonew&pid=15-message&guid=
Source: WiseCare365.exe, 00000009.00000003.2000308909.00000000055D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://karadzha.weebly.com/
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp String found in binary or memory: http://madExcept.comU
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ocsps.ssl.com0
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ocsps.ssl.com0?
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://service.weibo.com/share/share.php?url=https%3A%2F%2Fwww.wisecleaner.com.cn
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://sslcom.crl.certum.pl/ctnca.crl0s
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://sslcom.ocsp-certum.com08
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://sslcom.repository.certum.pl/ctnca.cer0:
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://tieba.baidu.com/f/commit/share/openShareApi?url=https://www.wisecleaner.com.cnU
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.addthis.com/bookmark.php?v=300&winname=addthis&pub=ra-4f87d17a70e638da&source=tbx32-300&l
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1671935264.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2052358843.000000000461F000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2017922213.00000000054E0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1679146180.0000000003410000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dk-soft.org/
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.0000000002195000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1671935264.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1679146180.0000000003410000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.0000000002240000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.haysoft.org%1-k
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000000.1959149673.0000000000D7C000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.indyproject.org/
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FBC0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000000.1677136447.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.innosetup.com/
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FBC0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000000.1677136447.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.remobjects.com/ps
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://www.ssl.com/repository/SSLcom-RootCA-EV-RSA-4096-R2.crt0
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt0
Source: WiseCare365.exe, 00000009.00000002.2956134333.00000000053E2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.w3.
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.com/&via=wisecleaner
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/AutoShutdown.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/AutoShutdown.svgll
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/DataRecovery.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/DataRecovery.svgll
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/DuplicateFinder.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/FastSearch.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/FolderHider.svg
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/ForceDeleter.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/ForceDeleter.svgll
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/GameBooster.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/MemoryOptimizer.svg
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/ProgramUninstaller.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/ProgramUninstaller.svgP
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.com/toolbox/imagesv6/Reminder.svg
Source: WiseCare365.exe String found in binary or memory: http://www.wisecleaner.net/install_statistics/index.php?p=install_statistics
Source: WiseCare365.exe, 00000009.00000002.2930766031.0000000000D32000.00000020.00000001.01000000.00000008.sdmp, WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/install_statistics/index.php?p=install_statisticsl(
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/software_statistics/index.php?p=comment_status
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/software_statistics/index.php?p=post_ad
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/software_statistics/v6.php?p=insertstart
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2930766031.0000000000A6F000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wiseclean
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=fetch-unread-message
Source: WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=fetch-unread-message&guid=
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=home
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=my-feedback
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=my-feedbackSV
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=question
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=upload-fileU
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=write-questionhttp://www.wisecleaner.ne
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WASSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195640841.000000000A783000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A77C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WDFSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WDRSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WFDSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195640841.000000000A783000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A77C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WFHSetup_5.0.2.232.exe
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WFHSetup_5.0.2.232.exel
Source: WiseCare365.exe, 00000009.00000003.2040735203.00000000073A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WFHSetup_5.0.5.235.exe
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WFHSetup_5.0.5.235.exel
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WGBSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WJSSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WMOSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WPUSetup.exe
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003371000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://downloads.wisecleaner.com/soft/WRMSetup.exe
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://feedback.wisecleaner.net/index.php?to=addSV
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://forum.wisecleaner.com/U
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://forum.wisecleaner.com/index.php?/topic/18165-how-to-fix-the-issue-of-you-are-possibly-a-vict
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82C2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82FF000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://g.live.com/odclientsettings/Prod.C:
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82C2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://g.live.com/odclientsettings/ProdV2
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82A3000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C:
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82C2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96
Source: WiseCare365.exe, 00000009.00000002.2937181357.00000000018B8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://info.wisecleaner.com/eK
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://info.wisecleaner.com/messages/index.php?to=checknews&pid=%dU
Source: WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://info.wisecleaner.com/messages/index.php?to=checknews&pid=3
Source: WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://info.wisecleaner.com/messages/index.php?to=checknews&pid=3L
Source: WiseCare365.exe, 00000009.00000002.2969270730.000000000A6E0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://info.wisecleaner.com/messages/index.php?to=checknews&pid=3y
Source: WiseCare365.exe, 00000009.00000002.2937181357.00000000018B8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://info.wisecleaner.com:443/messages/index.php?to=checknews&pid=3
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D82C2000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://oneclient.sfx.ms/Win/Installers/23.194.0917.0001/amd64/OneDriveSetup.exe
Source: svchost.exe, 0000000A.00000003.1977067538.000001A0D8256000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe.C:
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003438000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pdf.wisecleaner.com:52:00
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://reg.wisecleaner.com/order/checkregtime.php?email=%s&itemid=%d&code=%s&ver=%d
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://reg.wisecleaner.com/order/regchecker.php?email=%s&fname=%s&lname=%s&itemid=%d&code=%s&ver=6
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?url=https%3A%2F%2Fwww.wisecleaner.com.cn
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://twitter.com/share?original_referer=http://www.wisecleaner.com/&source=tweetbutton&text=Fast
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://wisecleaner.com/help/wisecare365/
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://wisecleaner.net/software_statistics/wiserate.txtU
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://wisecleaner.wordpress.com/2017/05/08/solution-for-compatibility-issue-between-wisecleaner-an
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: https://www.certum.pl/CPS0
Source: WiseCare365.exe, 00000009.00000003.2021079787.00000000055D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.geogeo.gr
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=JL84FKE78HWB4
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: https://www.ssl.com/repository0
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.00000000022BA000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.0000000002371000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942037803.00000000019A8000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000199D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1671935264.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1679146180.0000000003410000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/8https://www.wisecleaner.com/8https://www.wisecleaner.com/
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.00000000022BA000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/a
Source: WiseCare365.exe, 00000009.00000002.2942769828.00000000033F6000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/blog_sort_8.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/disc/?day=%d&pix=%.2f
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.0000000002240000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2015147366.0000000003509000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.00000000022E3000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/eula.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/eula.htmlSV
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/feedback.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/how-to-uninstall-wisecleaner-product.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/language.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/news/w365info.htmU
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.0000000002240000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2015147366.0000000003509000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.00000000022E3000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/privacy.html
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.00000000022BA000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/q
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/renew-license.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/software_update/getinfo_v6.php?p_id=31
Source: WiseCare365.exe, 00000009.00000002.2969532020.000000000A6FF000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A709000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A709000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000199D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/software_update/getinfo_v6.php?p_id=31&s_build=636
Source: WiseCare365.exe, 00000009.00000003.2165276598.000000000199D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/software_update/getinfo_v6.php?p_id=31&s_build=636O
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.00000000008EA000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.00000000008B8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.00000000022F4000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2047624216.0000000000918000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html0O:
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2047624216.000000000091E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html3
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2047624216.000000000091E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html56-
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2047624216.0000000000918000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlM
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2047624216.000000000091E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlY
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2029584048.000000000090D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmli
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1990302833.0000000000931000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2048171058.0000000000940000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.htmlz
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/theme/themesv6U
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/AutoShutdown.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/AutoShutdown.svgl
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/DataRecovery.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/DataRecovery.svgl
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195640841.000000000A783000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A77C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/DuplicateFinder.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/DuplicateFinder.svgP
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/FastSearch.svg
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195640841.000000000A783000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2193642376.000000000A77C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/FolderHider.svg
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/ForceDeleter.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/ForceDeleter.svgl
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/GameBooster.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/GameBooster.svgll
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/MemoryOptimizer.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/MemoryOptimizer.svggP
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/ProgramUninstaller.svg
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2195684775.0000000009EE0000.00000004.00000800.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2942769828.0000000003398000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2723424617.000000000A72C000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000196C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/imagesv6/Reminder.svg
Source: WiseCare365.exe, 00000009.00000002.2942769828.00000000033F6000.00000004.00001000.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000002.2941939880.00000000019A1000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2165276598.000000000199D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/toolsv6.ini
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/toolbox/toolsv6.ini3
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/upgrade-wisecare365.html
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.com/wise-care-365.html
Source: WiseCare365.exe, 00000009.00000002.2937181357.00000000018B8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com:443/software_update/getinfo_v6.php?p_id=31&s_build=636
Source: WiseCare365.exe, 00000009.00000002.2937181357.00000000018B8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.com:443/toolbox/toolsv6.ini
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/software_statistics/index.php?p=comment_status
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/software_statistics/index.php?p=post_ad
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/software_statistics/index.php?p=post_imageU
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/software_statistics/v6.php?p=insertstart
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/software_statistics/v6.php?p=post_product_infoU
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/start_mgr/index.php?to=add
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/start_mgr/index.php?to=query
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.0000000002248000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1671935264.0000000002510000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2015147366.00000000034D5000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.1679146180.0000000003410000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2021818558.0000000002240000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000003.2017922213.0000000005410000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.wisecleaner.net/uninstallfeedback/index.php?product=w365&ver=6.66
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/webnotify_mgr/index.php?to=add
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://www.wisecleaner.net/webnotify_mgr/index.php?to=query
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49865
Source: unknown Network traffic detected: HTTP traffic on port 49817 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49863
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49862
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49861
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49860
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49875 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49859
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49858
Source: unknown Network traffic detected: HTTP traffic on port 49881 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49857
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49856
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49841 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49854
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49853
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49852
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49851
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49850
Source: unknown Network traffic detected: HTTP traffic on port 49812 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49858 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49893 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49823 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49849
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49848
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49847
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49869 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49842
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49841
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49840
Source: unknown Network traffic detected: HTTP traffic on port 49834 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49892 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49828 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49839
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49838
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49837
Source: unknown Network traffic detected: HTTP traffic on port 49847 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49836
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49835
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49834
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49833
Source: unknown Network traffic detected: HTTP traffic on port 49887 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49832
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49831
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49830
Source: unknown Network traffic detected: HTTP traffic on port 49839 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49822 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49870 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49853 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49829
Source: unknown Network traffic detected: HTTP traffic on port 49811 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49828
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49827
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49826
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49825
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49824
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49823
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49822
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49836 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49885 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49895
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49894
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49893
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49892
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49891
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49911 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49802 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49851 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49889
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49888
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49887
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49886
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49885
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 49863 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49884
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49882
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49881
Source: unknown Network traffic detected: HTTP traffic on port 49840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49824 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49879
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49878
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49875
Source: unknown Network traffic detected: HTTP traffic on port 49891 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49874
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49818 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49870
Source: unknown Network traffic detected: HTTP traffic on port 49835 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49874 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49829 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49869
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49866
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49878 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49826 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49849 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49889 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49866 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49837 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49820 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49861 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49901 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49819 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49831 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49672
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 49814 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790
Source: unknown Network traffic detected: HTTP traffic on port 49856 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49895 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49821
Source: unknown Network traffic detected: HTTP traffic on port 49865 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49820
Source: unknown Network traffic detected: HTTP traffic on port 49842 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49859 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49833 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49819
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49818
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49817
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49816
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49815
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49814
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49813
Source: unknown Network traffic detected: HTTP traffic on port 49902 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49812
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49811
Source: unknown Network traffic detected: HTTP traffic on port 49816 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49827 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805
Source: unknown Network traffic detected: HTTP traffic on port 49848 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49882 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49803
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49802
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49838 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49821 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49815 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49854 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49914 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49860 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49914
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49911
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49832 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49902
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49901
Source: unknown Network traffic detected: HTTP traffic on port 49888 -> 443
Source: unknown HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49911 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49909 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.2.143:443 -> 192.168.2.4:49910 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49914 version: TLS 1.2

System Summary

barindex
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: is-UR7HO.tmp.1.dr Zip Entry: encrypted
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1786E0: DeviceIoControl,ReadFile,__aulldiv,ReadFile,__aulldiv, 9_2_6C1786E0
Source: C:\Windows\System32\svchost.exe File created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C185D2B 9_2_6C185D2B
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C18A778 9_2_6C18A778
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17F0AB 9_2_6C17F0AB
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17FA50 9_2_6C17FA50
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1D1C00 9_2_6C1D1C00
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22EC40 9_2_6C22EC40
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C225C50 9_2_6C225C50
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1A7C60 9_2_6C1A7C60
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1BCD00 9_2_6C1BCD00
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23CDB0 9_2_6C23CDB0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C248E0C 9_2_6C248E0C
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23BE90 9_2_6C23BE90
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1F3EA0 9_2_6C1F3EA0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1BDEC0 9_2_6C1BDEC0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C21DF70 9_2_6C21DF70
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23DFE0 9_2_6C23DFE0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C21B830 9_2_6C21B830
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1A4930 9_2_6C1A4930
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C212970 9_2_6C212970
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23DA20 9_2_6C23DA20
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1B8A30 9_2_6C1B8A30
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C24EAEB 9_2_6C24EAEB
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1A7B00 9_2_6C1A7B00
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C234B00 9_2_6C234B00
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C231B60 9_2_6C231B60
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23AB50 9_2_6C23AB50
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22BBE0 9_2_6C22BBE0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C252409 9_2_6C252409
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C214490 9_2_6C214490
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23C510 9_2_6C23C510
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23D570 9_2_6C23D570
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C20F540 9_2_6C20F540
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1A65A0 9_2_6C1A65A0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C24E59A 9_2_6C24E59A
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1FD5F0 9_2_6C1FD5F0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1BE604 9_2_6C1BE604
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23D660 9_2_6C23D660
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C21F770 9_2_6C21F770
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1FB790 9_2_6C1FB790
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C234020 9_2_6C234020
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C25004E 9_2_6C25004E
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C24E049 9_2_6C24E049
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23D0B0 9_2_6C23D0B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1AC0D0 9_2_6C1AC0D0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1AB0D0 9_2_6C1AB0D0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1EE0C0 9_2_6C1EE0C0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C2020C5 9_2_6C2020C5
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22F110 9_2_6C22F110
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1FA1B0 9_2_6C1FA1B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C24F1C7 9_2_6C24F1C7
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1F11E0 9_2_6C1F11E0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1C1250 9_2_6C1C1250
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C25424E 9_2_6C25424E
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1F7310 9_2_6C1F7310
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C20B350 9_2_6C20B350
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23D3A0 9_2_6C23D3A0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C20D3B0 9_2_6C20D3B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C1A6E10 appears 151 times
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C1A61C0 appears 187 times
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C1A5F90 appears 61 times
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C1C40B0 appears 95 times
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C17AEA0 appears 32 times
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: String function: 6C1A6040 appears 37 times
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-0KH1K.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-0KH1K.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-5N4PF.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (native) Intel 80386, for MS Windows
Source: is-5N4PF.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (native) x86-64, for MS Windows
Source: is-5N4PF.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (native) Intel 80386, for MS Windows
Source: is-5N4PF.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (native) x86-64, for MS Windows
Source: is-06S8G.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: is-0OCO8.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: is-HBE50.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: is-LTPNS.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: is-NN1JK.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000000.1671113651.00000000004B8000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFileName vs SecuriteInfo.com.FileRepPup.14974.19067.exe
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1675565955.000000007FE29000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs SecuriteInfo.com.FileRepPup.14974.19067.exe
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.1673743740.000000000277D000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs SecuriteInfo.com.FileRepPup.14974.19067.exe
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe, 00000000.00000003.2057537991.0000000002278000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamekernel32j% vs SecuriteInfo.com.FileRepPup.14974.19067.exe
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Binary or memory string: OriginalFileName vs SecuriteInfo.com.FileRepPup.14974.19067.exe
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus32.evad.winEXE@30/516@53/22
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Mutant created: \Sessions\1\BaseNamedObjects\madExceptSettingsMtx$1608
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Mutant created: NULL
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Mutant created: \Sessions\1\BaseNamedObjects\HookTThread$1608
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Mutant created: \Sessions\1\BaseNamedObjects\madExceptSettingsMtx$12cc
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Mutant created: \Sessions\1\BaseNamedObjects\HookTThread$12cc
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5264:120:WilError_03
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Mutant created: \Sessions\1\BaseNamedObjects\Wise365Mutex2018
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe File created: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp Jump to behavior
Source: Yara match File source: 12.0.BootTime.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 14.0.WiseTray.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.0.WiseCare365.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000C.00000000.2045282560.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000000.2133553791.0000000000401000.00000020.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-686UE.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-06S8G.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-NN1JK.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-LTPNS.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-0OCO8.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\Wise\Wise Care 365\is-HBE50.tmp, type: DROPPED
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Key opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
Source: WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: WiseCare365.exe Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zerobl
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: WiseCare365.exe, WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe ReversingLabs: Detection: 15%
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Virustotal: Detection: 12%
Source: WiseCare365.exe String found in binary or memory: http://www.wisecleaner.net/install_statistics/index.php?p=install_statistics
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe String found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe "C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Process created: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp "C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp" /SL5="$1045C,19204712,857088,C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe"
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /delete /tn \WiseCleaner\W365SkipUAC /f
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe"
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=1076,i,16708299124163291726,5417237086903671621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe "C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe"
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Process created: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp "C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp" /SL5="$1045C,19204712,857088,C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /delete /tn \WiseCleaner\W365SkipUAC /f Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=1076,i,16708299124163291726,5417237086903671621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: ieframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wkscli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: msiso.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: mlang.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: policymanager.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: sqlite3.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wjslib.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: faultrep.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: security.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: spp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: slc.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: idndl.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: webio.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: qmgr.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: bitsperf.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: firewallapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: esent.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: fwbase.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: flightsettings.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: netprofm.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: npmproxy.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: bitsigd.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: upnp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ssdpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: appxdeploymentclient.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wsmauto.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wsmsvc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dsrole.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: pcwum.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: msv1_0.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ntlmshared.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptdll.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: webio.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: rmclient.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: usermgrcli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelclient.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelproxy.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: samlib.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: es.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: bitsproxy.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: faultrep.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: Wise Care 365.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe
Source: Uninstall Wise Care 365.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Wise\Wise Care 365\unins000.exe
Source: Wise Care 365.lnk0.1.dr LNK file: ..\..\..\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File written: C:\Users\user\AppData\Roaming\Wise Care 365\config.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: certificate valid
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static file information: File size 20168536 > 1048576
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: G:\workspace\windows\NewToolsProject\SQLite3Encrypt\Release\SQLite3Encrypt.pdb source: WiseCare365.exe, 00000009.00000002.2973825497.000000006C255000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: G:\workspace\windows\WiseCare365_V4\Bootlancher\Release\Bootlauncher.pdb source: SecuriteInfo.com.FileRepPup.14974.19067.tmp, 00000001.00000002.2037855665.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C244D98 DecodePointer,LoadLibraryW,GetProcAddress,GetLastError,GetLastError,GetLastError,EncodePointer,InterlockedExchange,FreeLibrary, 9_2_6C244D98
Source: SecuriteInfo.com.FileRepPup.14974.19067.exe Static PE information: section name: .didata
Source: SecuriteInfo.com.FileRepPup.14974.19067.tmp.0.dr Static PE information: section name: .didata
Source: is-0KH1K.tmp.1.dr Static PE information: section name: .didata
Source: is-06S8G.tmp.1.dr Static PE information: section name: .didata
Source: is-NN1JK.tmp.1.dr Static PE information: section name: .didata
Source: is-HBE50.tmp.1.dr Static PE information: section name: .didata
Source: is-VM9DB.tmp.1.dr Static PE information: section name: .didata
Source: is-5N4PF.tmp.1.dr Static PE information: section name: .didata
Source: is-LTPNS.tmp.1.dr Static PE information: section name: .didata
Source: is-0OCO8.tmp.1.dr Static PE information: section name: .didata
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17AEE6 push ecx; ret 9_2_6C17AEF9
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C247575 push ecx; ret 9_2_6C247588
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-Q90PB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-VM9DB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-2137K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-HBE50.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WJSLib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-0KH1K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\sqlite3.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-TBFAC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-5N4PF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-0OCO8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\BootLauncher.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\AutoUpdate.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseEraser.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\DManager.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-RHK8R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-KVUKP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\ssleay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Users\user\AppData\Local\Temp\is-1Q5HG.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-06S8G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\libeay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe File created: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-ML9G6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-686UE.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-LTPNS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseDefrag.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\is-NN1JK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Program Files (x86)\Wise\Wise Care 365\WiseBootBooster.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\Users\user\AppData\Local\Temp\is-1Q5HG.tmp\license.txt Jump to behavior

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /delete /tn \WiseCleaner\W365SkipUAC /f
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WiseBootAssistant Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365\Wise Care 365.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365\Uninstall Wise Care 365.lnk Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepPup.14974.19067.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\WiseEraser.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-Q90PB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-VM9DB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\DManager.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-2137K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-RHK8R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-KVUKP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\ssleay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-06S8G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-1Q5HG.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\libeay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-TBFAC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-5N4PF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-0OCO8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-ML9G6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\BootLauncher.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\AutoUpdate.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\WiseDefrag.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\WiseBootBooster.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Wise\Wise Care 365\is-NN1JK.tmp Jump to dropped file
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe API coverage: 0.5 %
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Registry key enumerated: More than 497 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Windows\System32\svchost.exe TID: 7428 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Windows\System32\svchost.exe File opened: PhysicalDrive0 Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%LOCAL_APPDATA%\\Temp\\vmware-11"],
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Microsoft Hyper-V Server
Source: WiseCare365.exe, 00000009.00000003.2023586128.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=Client VMware Horizon
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%LOCAL_APPDATA%\\VMware\\VDM\\logs",
Source: WiseCare365.exe, 00000009.00000003.1988728149.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon Client (
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Datacenter without Hyper-V Core
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Standard without Hyper-V Full
Source: WiseTray.exe, 0000000E.00000002.2945131329.00000000047F9000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: )VMwareHorizonClient=VMware Horizon Client\
Source: WiseCare365.exe, 00000009.00000000.1965205495.0000000000E38000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: [vmicheartbeat]
Source: WiseCare365.exe, 00000009.00000003.2014804518.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon(u6b
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Enterprise without Hyper-V Core
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%PROGRAM_FILES%\\Common Files\\VMware\\InstallerCache"
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "paths": ["%PROGRAM_FILES%\\VMware\\VMware Workstation\\ico"
Source: WiseCare365.exe, 00000009.00000000.1965205495.0000000000E38000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: [vmicvss]
Source: WiseCare365.exe, 00000009.00000003.2193642376.000000000A727000.00000004.00000020.00020000.00000000.sdmp, WiseCare365.exe, 00000009.00000003.2725090030.000000000194E000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2932451581.000001A0D2A2B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2937332047.000001A0D8054000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "defaultname": "VMware Workstation",
Source: WiseCare365.exe, 00000009.00000003.2018419880.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon asiakas tiedot
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%common_appdata%\\VMware\\VDM\\logs",
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "paths": ["%LOCAL_APPDATA%\\VMware"
Source: WiseTray.exe, 0000000E.00000002.2937712728.0000000001243000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: )VMwareHorizonClient=VMware Horizon Client
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%programfiles%\\VMware\\VMware Horizon View Client"],
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "exclude": ["VMwareDnD"]
Source: WiseCare365.exe, 00000009.00000003.2026034506.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon-klient
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "paths": ["%common_appdata%\\VMware\\logs",
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: 6without Hyper-V for Windows Essential Server Solutions
Source: WiseCare365.exe, 00000009.00000002.2942769828.0000000003438000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: )VMwareHorizonClient=VMware Horizon ClientA
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: )VMwareHorizonClient=VMware Horizon ClientoSp]K
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "VMwareHorizonClient": {
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "VMwareWorkstationPro": {
Source: WiseCare365.exe, 00000009.00000003.2035963945.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon 0
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%common_appdata%\\VMware\\vmwetlm\\logs",
Source: WiseCare365.exe, 00000009.00000000.1965205495.0000000000E38000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: [vmicshutdown]
Source: WiseCare365.exe, 00000009.00000002.2961151274.000000000541F000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: )VMwareHorizonClient=VMware Horizon Clientnn
Source: WiseCare365.exe, 00000009.00000003.2032856067.00000000055D0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareHorizonClient=VMware Horizon Client
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Standard without Hyper-V Core
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%PROGRAM_FILES%\\VMware\\VMware Workstation"],
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "%common_appdata%\\VMware\\logs",
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Datacenter without Hyper-V Full
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "exists": ["HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\vmware-view(Reg)",
Source: WiseCare365.exe, 00000009.00000000.1959149673.0000000000401000.00000020.00000001.01000000.00000008.sdmp, WiseTray.exe, 0000000E.00000000.2133553791.0000000000449000.00000020.00000001.01000000.0000000F.sdmp Binary or memory string: Enterprise without Hyper-V Full
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "pathmatch": ["vmware-.*"],
Source: WiseCare365.exe, 00000009.00000000.1965205495.00000000015DC000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: "defaultname": "VMware Horizon Client",
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17B22B IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_6C17B22B
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C244D98 DecodePointer,LoadLibraryW,GetProcAddress,GetLastError,GetLastError,GetLastError,EncodePointer,InterlockedExchange,FreeLibrary, 9_2_6C244D98
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C181191 mov eax, dword ptr fs:[00000030h] 9_2_6C181191
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C18511F GetProcessHeap, 9_2_6C18511F
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process token adjusted: Debug Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process token adjusted: Debug Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17AC52 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 9_2_6C17AC52
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17B22B IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_6C17B22B
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C180285 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_6C180285
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C245984 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_6C245984
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C243AA6 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 9_2_6C243AA6
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.wisecleaner.com/thanks-for-choosing-WiseCare365.html Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe" Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Process created: C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe "C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe" Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17B47B cpuid 9_2_6C17B47B
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-0JG3C.tmp\SecuriteInfo.com.FileRepPup.14974.19067.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C17B34E GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 9_2_6C17B34E
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C24601B __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_strcpy_s,__invoke_watson,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,WideCharToMultiByte, 9_2_6C24601B
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22DCF0 sqlite3_initialize,sqlite3_free,sqlite3_bind_int64,sqlite3_free,sqlite3_step,sqlite3_reset, 9_2_6C22DCF0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22FD70 sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C22FD70
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C230D40 sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C230D40
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAD60 sqlite3_bind_blob, 9_2_6C1CAD60
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAD90 sqlite3_bind_blob64, 9_2_6C1CAD90
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22DDE0 sqlite3_initialize,sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,_memset,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free, 9_2_6C22DDE0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CADE0 sqlite3_bind_double, 9_2_6C1CADE0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C230E10 sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_reset, 9_2_6C230E10
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22FE70 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C22FE70
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAE90 sqlite3_bind_int,sqlite3_bind_int64, 9_2_6C1CAE90
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAEB0 sqlite3_bind_int64, 9_2_6C1CAEB0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAF30 sqlite3_bind_null, 9_2_6C1CAF30
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C229F70 sqlite3_bind_int64,sqlite3_bind_value,sqlite3_step,sqlite3_reset, 9_2_6C229F70
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAF60 sqlite3_bind_text, 9_2_6C1CAF60
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAF90 sqlite3_bind_text64, 9_2_6C1CAF90
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CAFF0 sqlite3_bind_text16, 9_2_6C1CAFF0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C238820 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C238820
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C231810 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C231810
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C238870 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C238870
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C221840 sqlite3_finalize,sqlite3_free,sqlite3_free,_memset,sqlite3_value_numeric_type,sqlite3_value_numeric_type,sqlite3_blob_close,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_bind_value, 9_2_6C221840
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C239A00 sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C239A00
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22DA70 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_reset, 9_2_6C22DA70
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C237A80 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset, 9_2_6C237A80
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C231B60 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_mprintf,sqlite3_finalize,sqlite3_free,sqlite3_step,sqlite3_column_text,sqlite3_column_bytes, 9_2_6C231B60
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23AB50 sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C23AB50
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB470 sqlite3_transfer_bindings, 9_2_6C1CB470
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C2364B0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_initialize,sqlite3_reset,sqlite3_free,__allrem, 9_2_6C2364B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22B500 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_mprintf,sqlite3_free,sqlite3_step,sqlite3_reset, 9_2_6C22B500
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C2295A0 sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset, 9_2_6C2295A0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C229630 sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset, 9_2_6C229630
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C23A6F0 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,__allrem,sqlite3_free,__allrem,sqlite3_free, 9_2_6C23A6F0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22E720 _memset,sqlite3_initialize,_memset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset, 9_2_6C22E720
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C230710 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, 9_2_6C230710
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C236760 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,__allrem, 9_2_6C236760
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C229770 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64, 9_2_6C229770
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22F790 sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C22F790
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22F7F0 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_free,sqlite3_free,sqlite3_initialize,_memset,sqlite3_initialize,sqlite3_initialize,sqlite3_free,sqlite3_reset,sqlite3_reset, 9_2_6C22F7F0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB020 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_zeroblob, 9_2_6C1CB020
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22E070 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_step,sqlite3_reset,sqlite3_blob_close, 9_2_6C22E070
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C230040 sqlite3_bind_int64,sqlite3_step,sqlite3_initialize,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C230040
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22C0E0 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset, 9_2_6C22C0E0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22C1B0 sqlite3_bind_int64,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset, 9_2_6C22C1B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB1A0 sqlite3_bind_zeroblob, 9_2_6C1CB1A0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C21F230 sqlite3_mprintf,sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code, 9_2_6C21F230
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB230 sqlite3_bind_zeroblob64,sqlite3_bind_zeroblob, 9_2_6C1CB230
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22C250 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C22C250
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1C9260 sqlite3_clear_bindings, 9_2_6C1C9260
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB2B0 sqlite3_bind_parameter_count, 9_2_6C1CB2B0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB2D0 sqlite3_bind_parameter_name, 9_2_6C1CB2D0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22D2C0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,sqlite3_bind_int64,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,sqlite3_bind_int64,sqlite3_step,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_step,sqlite3_reset,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset, 9_2_6C22D2C0
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C229310 sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_bind_value, 9_2_6C229310
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22A370 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset, 9_2_6C22A370
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C1CB360 sqlite3_bind_parameter_index, 9_2_6C1CB360
Source: C:\Program Files (x86)\Wise\Wise Care 365\WiseCare365.exe Code function: 9_2_6C22B3F0 sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 9_2_6C22B3F0
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs