Windows Analysis Report
AdvancedReclaiMeFreeRAIDRecoveryFreeSetup.msi

Overview

General Information

Sample name: AdvancedReclaiMeFreeRAIDRecoveryFreeSetup.msi
Analysis ID: 1432009
MD5: 3f79740f726f7d412336fafc9feba28f
SHA1: f5580579105ac3dde64bd65fd1371fa8c5313e70
SHA256: a4781c64764c1c030790269eae5f56e6a56edaac3f548db5caeb46b65acc6735
Infos:

Detection

DanaBot
Score: 96
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for dropped file
Yara detected DanaBot stealer dll
Adds a directory exclusion to Windows Defender
Found many strings related to Crypto-Wallets (likely being stolen)
Loading BitLocker PowerShell Module
May use the Tor software to hide its network traffic
PE file has a writeable .text section
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Registers a new ROOT certificate
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Abnormal high CPU Usage
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to create an SMB header
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries the installation date of Windows
Queries the product ID of Windows
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Powershell Defender Exclusion
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

Name Description Attribution Blogpost URLs Link
DanaBot Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be monetized rather than demanding an immediate ransom from victims. The social engineering in the low-volume DanaBot campaigns we have observed so far has been well-crafted, again pointing to a renewed focus on quality over quantity in email-based threats. DanaBots modular nature enables it to download additional components, increasing the flexibility and robust stealing and remote monitoring capabilities of this banker.
  • SCULLY SPIDER
https://malpedia.caad.fkie.fraunhofer.de/details/win.danabot

AV Detection

barindex
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\ActivityTracesHelper.dll Virustotal: Detection: 8% Perma Link
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libmodel.dll Virustotal: Detection: 14% Perma Link
Source: Yara match File source: 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1308078998.0000000009501000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1293571064.0000000008435000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1305389223.0000000009500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1301409791.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: BackupExtractor.exe PID: 5328, type: MEMORYSTR
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70CCC CRYPTO_free,strlen,CRYPTO_strdup,ERR_put_error,ERR_put_error,ERR_put_error, 19_2_6CC70CCC
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAACD9 EVP_PKEY_get0_RSA,RSA_size,RSA_size,CRYPTO_malloc,RAND_priv_bytes,RSA_private_decrypt,CRYPTO_free, 19_2_6CCAACD9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78CD9 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free, 19_2_6CC78CD9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92CE7 CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC92CE7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA8C87 CRYPTO_free,CRYPTO_free, 19_2_6CCA8C87
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78C88 CRYPTO_free,CRYPTO_free, 19_2_6CC78C88
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70C98 CRYPTO_free, 19_2_6CC70C98
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9ACA8 memcmp,CRYPTO_free,memcmp,memcmp,EVP_CIPHER_CTX_free,CRYPTO_free,memcmp,CRYPTO_free,CRYPTO_free, 19_2_6CC9ACA8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64CA0 CRYPTO_zalloc,ERR_put_error, 19_2_6CC64CA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC72C49 CRYPTO_clear_free,CRYPTO_clear_free, 19_2_6CC72C49
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC72C67 CRYPTO_clear_free, 19_2_6CC72C67
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7CC70 CRYPTO_free,BUF_MEM_free,EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,COMP_CTX_free,COMP_CTX_free,EVP_MD_CTX_free,EVP_MD_CTX_free,EVP_MD_CTX_free,X509_free,X509_VERIFY_PARAM_move_peername,CRYPTO_free,ERR_put_error,ERR_put_error, 19_2_6CC7CC70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92C74 CRYPTO_free,CRYPTO_memdup,CRYPTO_memdup, 19_2_6CC92C74
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7CC11 CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error, 19_2_6CC7CC11
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC80C13 ERR_put_error,CRYPTO_free, 19_2_6CC80C13
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCACDC3 EVP_CIPHER_key_length,EVP_CIPHER_iv_length,CRYPTO_malloc, 19_2_6CCACDC3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC98DC7 OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 19_2_6CC98DC7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78DE0 BIO_snprintf,CRYPTO_malloc,ERR_put_error, 19_2_6CC78DE0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB4DE0 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 19_2_6CCB4DE0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA8DF9 CRYPTO_free,CRYPTO_free, 19_2_6CCA8DF9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64DF0 CRYPTO_free, 19_2_6CC64DF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB0DF0 CRYPTO_free, 19_2_6CCB0DF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92D8C CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC92D8C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC82D90 OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,X509_free,OPENSSL_sk_new_reserve,OPENSSL_sk_value,X509_VERIFY_PARAM_get_depth,X509_VERIFY_PARAM_set_depth,CRYPTO_dup_ex_data,EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,COMP_CTX_free,COMP_CTX_free,EVP_MD_CTX_free,EVP_MD_CTX_free,X509_VERIFY_PARAM_inherit,OPENSSL_sk_dup,OPENSSL_sk_dup,memcpy,ERR_put_error,ERR_put_error, 19_2_6CC82D90
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCACD90 EVP_CIPHER_key_length,EVP_CIPHER_iv_length,CRYPTO_malloc, 19_2_6CCACD90
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92D40 CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC92D40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC88D53 CRYPTO_realloc,memcpy,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error, 19_2_6CC88D53
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC80D70 X509_VERIFY_PARAM_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,X509_free,CRYPTO_free_ex_data,BIO_pop,BIO_free,BIO_free_all,BIO_free_all,BUF_MEM_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,COMP_CTX_free,COMP_CTX_free,EVP_MD_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,SCT_LIST_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,ASYNC_WAIT_CTX_free,CRYPTO_free,OPENSSL_sk_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 19_2_6CC80D70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC98EC9 OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 19_2_6CC98EC9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC84EDB CRYPTO_malloc,CRYPTO_free,ERR_put_error, 19_2_6CC84EDB
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64ED0 CRYPTO_free,CRYPTO_free, 19_2_6CC64ED0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB4EF0 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 19_2_6CCB4EF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8AE97 CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 19_2_6CC8AE97
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC94EA0 CRYPTO_free, 19_2_6CC94EA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA4EA0 CRYPTO_malloc,memcpy, 19_2_6CCA4EA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA0E62 CRYPTO_malloc,memcpy,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_put_error,EVP_CIPHER_CTX_free,EVP_MD_CTX_free, 19_2_6CCA0E62
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8AE70 CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock, 19_2_6CC8AE70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66E36 CRYPTO_free, 19_2_6CC66E36
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92E35 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_realloc,CRYPTO_free,CRYPTO_free, 19_2_6CC92E35
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9EFC0 CRYPTO_malloc,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_zalloc,ERR_put_error,CRYPTO_free,ERR_put_error, 19_2_6CC9EFC0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64FD0 CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow, 19_2_6CC64FD0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC76FE9 CRYPTO_zalloc,CRYPTO_free, 19_2_6CC76FE9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC72FF0 EVP_PKEY_CTX_new,EVP_PKEY_derive_init,EVP_PKEY_derive_set_peer,EVP_PKEY_derive,CRYPTO_malloc,EVP_PKEY_derive,CRYPTO_clear_free,EVP_PKEY_CTX_free, 19_2_6CC72FF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC90FF7 CRYPTO_strdup, 19_2_6CC90FF7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC88F80 BIO_s_file,BIO_new,BIO_ctrl,strncmp,CRYPTO_realloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free,PEM_read_bio,strlen,strncmp,CRYPTO_realloc,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,BIO_free,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error, 19_2_6CC88F80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8AF81 CRYPTO_THREAD_unlock, 19_2_6CC8AF81
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8AFB9 CRYPTO_THREAD_unlock, 19_2_6CC8AFB9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8EFB0 CRYPTO_malloc,memcpy, 19_2_6CC8EFB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC98F60 X509_get0_pubkey,EVP_PKEY_CTX_new,CRYPTO_malloc,EVP_PKEY_encrypt_init,RAND_bytes,EVP_MD_CTX_new,OBJ_nid2sn,EVP_get_digestbyname,EVP_DigestInit,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_MD_CTX_free,EVP_PKEY_CTX_ctrl,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_MD_CTX_free, 19_2_6CC98F60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6CF70 EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,COMP_expand_block,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,CRYPTO_memcmp,CRYPTO_malloc, 19_2_6CC6CF70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64F7C CRYPTO_free,CRYPTO_free, 19_2_6CC64F7C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC76F00 CRYPTO_zalloc,CRYPTO_free,ERR_put_error, 19_2_6CC76F00
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC768C4 CRYPTO_free, 19_2_6CC768C4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB08E0 CRYPTO_free,CRYPTO_malloc,ERR_put_error, 19_2_6CCB08E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC668A0 CRYPTO_free, 19_2_6CC668A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA08A3 CRYPTO_malloc,ERR_put_error,CRYPTO_free, 19_2_6CCA08A3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAA8A0 EVP_PKEY_CTX_new,EVP_PKEY_decrypt_init,X509_get0_pubkey,EVP_PKEY_derive_set_peer,ASN1_item_d2i,ASN1_TYPE_get,EVP_PKEY_decrypt,EVP_PKEY_CTX_ctrl,EVP_PKEY_CTX_free,ASN1_item_free,CRYPTO_clear_free,EVP_PKEY_new,EVP_PKEY_copy_parameters,EVP_PKEY_get0_DH,BN_bin2bn,DH_set0_key,EVP_PKEY_free,EVP_PKEY_free,EVP_PKEY_get0_RSA,RSA_size,RSA_size,CRYPTO_malloc,RAND_priv_bytes,RSA_private_decrypt,CRYPTO_free,EVP_PKEY_new,EVP_PKEY_copy_parameters,EVP_PKEY_set1_tls_encodedpoint,EVP_PKEY_free,EVP_PKEY_free,EVP_PKEY_free,BN_bin2bn,BN_ucmp,BN_is_zero,CRYPTO_free,CRYPTO_strdup,EVP_PKEY_CTX_free,ASN1_item_free,CRYPTO_free,BN_free,EVP_PKEY_free,ERR_clear_error,EVP_PKEY_free, 19_2_6CCAA8A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC80864 CRYPTO_zalloc,CRYPTO_THREAD_lock_new,OPENSSL_LH_new,X509_STORE_new,CTLOG_STORE_new,OPENSSL_sk_num,X509_VERIFY_PARAM_new,EVP_get_digestbyname,EVP_get_digestbyname,OPENSSL_sk_new_null,OPENSSL_sk_new_null,CRYPTO_new_ex_data,CRYPTO_secure_zalloc,RAND_bytes,RAND_priv_bytes,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_free,ERR_put_error,RAND_priv_bytes,RAND_priv_bytes,ERR_put_error,ERR_put_error, 19_2_6CC80864
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC76813 COMP_zlib,CRYPTO_mem_ctrl,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,COMP_get_name,OPENSSL_sk_push,OPENSSL_sk_sort,CRYPTO_mem_ctrl, 19_2_6CC76813
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC669C3 CRYPTO_free, 19_2_6CC669C3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC729E0 CRYPTO_malloc,memcpy,memcpy,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_malloc,memset,OPENSSL_cleanse,CRYPTO_clear_free, 19_2_6CC729E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC789EC OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_num,CRYPTO_free,OPENSSL_sk_dup,OPENSSL_sk_free,OPENSSL_sk_set_cmp_func,OPENSSL_sk_sort,OPENSSL_sk_free, 19_2_6CC789EC
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7C986 CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error, 19_2_6CC7C986
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA89A1 CRYPTO_zalloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CCA89A1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA69B5 CRYPTO_malloc,EVP_CIPHER_CTX_new,HMAC_CTX_new,EVP_CIPHER_CTX_iv_length,EVP_EncryptUpdate,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,EVP_MD_size,RAND_bytes,time,CRYPTO_free,CRYPTO_memdup,EVP_aes_256_cbc,EVP_CIPHER_iv_length,RAND_bytes,EVP_EncryptInit_ex,EVP_sha256,HMAC_Init_ex,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,EVP_EncryptFinal,HMAC_Update,HMAC_Final, 19_2_6CCA69B5
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9C976 CRYPTO_free, 19_2_6CC9C976
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64900 CRYPTO_zalloc,CRYPTO_free,ERR_put_error,BUF_MEM_grow, 19_2_6CC64900
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8A900 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock, 19_2_6CC8A900
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A917 COMP_expand_block,CRYPTO_malloc, 19_2_6CC6A917
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA0911 CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CCA0911
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAAAFC CRYPTO_clear_free, 19_2_6CCAAAFC
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9EA89 CRYPTO_free,CRYPTO_free,EVP_MD_CTX_new,X509_get0_pubkey,EVP_PKEY_size,BIO_free,EVP_MD_CTX_free,CRYPTO_free,EVP_PKEY_id,EVP_DigestVerifyInit,EVP_PKEY_id,EVP_DigestVerify,EVP_PKEY_id,EVP_PKEY_id,CRYPTO_malloc,BUF_reverse,EVP_DigestUpdate,EVP_MD_CTX_ctrl,EVP_DigestVerifyFinal,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,CRYPTO_memcmp,memcpy,memcpy, 19_2_6CC9EA89
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78AA4 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free, 19_2_6CC78AA4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64AA9 CRYPTO_zalloc,ERR_put_error,CRYPTO_zalloc,CRYPTO_free,BUF_MEM_grow, 19_2_6CC64AA9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8CA4C CRYPTO_free,CRYPTO_strdup, 19_2_6CC8CA4C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70A4C CRYPTO_free,CRYPTO_memdup, 19_2_6CC70A4C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9CA53 CRYPTO_free, 19_2_6CC9CA53
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9CA39 time,CRYPTO_free,CRYPTO_malloc,memcpy,EVP_sha256,EVP_Digest,EVP_MD_size,CRYPTO_free, 19_2_6CC9CA39
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC98BC0 strlen,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_free,CRYPTO_free,OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 19_2_6CC98BC0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC72BEC CRYPTO_clear_free, 19_2_6CC72BEC
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC72B81 CRYPTO_malloc,memset, 19_2_6CC72B81
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7CB9B CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error, 19_2_6CC7CB9B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC88BA0 CRYPTO_realloc,memcpy,ERR_put_error,ERR_put_error,ERR_put_error,ERR_put_error, 19_2_6CC88BA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC94BB3 EVP_MD_CTX_new,EVP_PKEY_new_raw_private_key,EVP_sha256,EVP_DigestSignInit,EVP_DigestSign,EVP_MD_CTX_free,EVP_PKEY_free,CRYPTO_memcmp, 19_2_6CC94BB3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66B58 CRYPTO_free,BIO_clear_flags,BIO_set_flags,memcpy,BIO_snprintf,ERR_add_error_data, 19_2_6CC66B58
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70B60 CONF_parse_list,CRYPTO_malloc,memcpy,CRYPTO_free, 19_2_6CC70B60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92B70 CRYPTO_memdup,CRYPTO_free,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free, 19_2_6CC92B70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70B18 CONF_parse_list,CRYPTO_malloc,memcpy,CRYPTO_free,CRYPTO_free,ERR_put_error, 19_2_6CC70B18
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78B36 CRYPTO_malloc,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free, 19_2_6CC78B36
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70B3A CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_put_error, 19_2_6CC70B3A
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC624C1 CRYPTO_free, 19_2_6CC624C1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9C4D0 time,CRYPTO_free,CRYPTO_malloc,memcpy,EVP_sha256,EVP_Digest,EVP_MD_size,CRYPTO_free,CRYPTO_free, 19_2_6CC9C4D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC624F7 CRYPTO_free, 19_2_6CC624F7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC644F0 CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow,BUF_MEM_grow, 19_2_6CC644F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8A4F0 CRYPTO_THREAD_write_lock,OPENSSL_LH_insert,CRYPTO_THREAD_unlock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,OPENSSL_LH_retrieve, 19_2_6CC8A4F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66480 CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC66480
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC62493 CRYPTO_free, 19_2_6CC62493
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC664B3 CRYPTO_malloc,CRYPTO_free,CRYPTO_free, 19_2_6CC664B3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC704B0 CRYPTO_zalloc, 19_2_6CC704B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8E4B3 OPENSSL_cleanse,OPENSSL_cleanse,EVP_PKEY_free,EVP_MD_CTX_free,EVP_DigestInit_ex,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_PKEY_new_raw_private_key,EVP_DigestSignInit,EVP_DigestUpdate,EVP_DigestSignFinal,CRYPTO_memcmp, 19_2_6CC8E4B3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8044B CRYPTO_free,CRYPTO_memdup,ERR_put_error, 19_2_6CC8044B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78440 ERR_put_error,CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,OPENSSL_sk_new_null,OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_num,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_dup,OPENSSL_sk_free,OPENSSL_sk_set_cmp_func,OPENSSL_sk_sort,OPENSSL_sk_free,CRYPTO_free,ERR_put_error,CRYPTO_free,ERR_put_error,CRYPTO_free, 19_2_6CC78440
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74450 CRYPTO_zalloc,CRYPTO_THREAD_lock_new,ERR_put_error,ERR_put_error,CRYPTO_free, 19_2_6CC74450
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9E47C EVP_MD_CTX_free,CRYPTO_free,CRYPTO_strndup, 19_2_6CC9E47C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74410 CRYPTO_THREAD_run_once, 19_2_6CC74410
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A430 CRYPTO_free,CRYPTO_malloc,CRYPTO_malloc, 19_2_6CC6A430
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C5C8 CRYPTO_free, 19_2_6CC8C5C8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC745E0 EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 19_2_6CC745E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7C5E0 EVP_MD_size,CRYPTO_zalloc,CRYPTO_malloc,memcpy,d2i_X509,X509_get0_pubkey,OPENSSL_sk_push,ERR_put_error,X509_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error,ERR_put_error,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error,ERR_put_error,d2i_PUBKEY,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_insert,ERR_put_error,ERR_put_error,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_put_error,EVP_PKEY_free,X509_free,OPENSSL_sk_new_null, 19_2_6CC7C5E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A5F7 CRYPTO_malloc, 19_2_6CC6A5F7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7C583 CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 19_2_6CC7C583
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAE580 CRYPTO_free, 19_2_6CCAE580
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB0550 CRYPTO_malloc,CRYPTO_free,CRYPTO_free,ERR_put_error, 19_2_6CCB0550
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A566 CRYPTO_malloc, 19_2_6CC6A566
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7850C CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free, 19_2_6CC7850C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC70510 EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_clear_free, 19_2_6CC70510
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7453B X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free, 19_2_6CC7453B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC706C0 CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC706C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C6E7 CRYPTO_free, 19_2_6CC8C6E7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA6680 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse, 19_2_6CCA6680
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A690 CRYPTO_free, 19_2_6CC6A690
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCB0690 CRYPTO_malloc,CRYPTO_free,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,ERR_put_error, 19_2_6CCB0690
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C6A1 CRYPTO_free, 19_2_6CC8C6A1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC80640 X509_VERIFY_PARAM_free,CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,ENGINE_finish,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 19_2_6CC80640
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C650 CRYPTO_free,CRYPTO_free, 19_2_6CC8C650
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC80664 X509_VERIFY_PARAM_free,CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,ENGINE_finish,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 19_2_6CC80664
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7460B EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 19_2_6CC7460B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C610 CRYPTO_free, 19_2_6CC8C610
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC96635 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free, 19_2_6CC96635
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8C78B CRYPTO_free,CRYPTO_free,CRYPTO_strdup, 19_2_6CC8C78B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6C794 CRYPTO_malloc, 19_2_6CC6C794
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A790 CRYPTO_free, 19_2_6CC6A790
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC94751 time,EVP_MD_CTX_new,EVP_PKEY_new_raw_private_key,EVP_sha256,EVP_DigestSignInit,EVP_DigestSign,EVP_MD_CTX_free,EVP_PKEY_free,CRYPTO_memcmp,EVP_MD_CTX_free,EVP_PKEY_free,EVP_MD_CTX_free,EVP_PKEY_free, 19_2_6CC94751
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66770 CRYPTO_free, 19_2_6CC66770
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74770 CRYPTO_zalloc,CRYPTO_THREAD_lock_new,EVP_PKEY_up_ref,X509_up_ref,EVP_PKEY_up_ref,X509_chain_up_ref,CRYPTO_malloc,memcpy,CRYPTO_malloc,memcpy,CRYPTO_malloc,memcpy,CRYPTO_memdup,X509_STORE_up_ref,X509_STORE_up_ref,CRYPTO_strdup,ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_free, 19_2_6CC74770
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAE770 CRYPTO_malloc,CRYPTO_free,CRYPTO_free,ERR_put_error,ERR_put_error, 19_2_6CCAE770
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A700 CRYPTO_free, 19_2_6CC6A700
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6670C CRYPTO_free,CRYPTO_free, 19_2_6CC6670C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA071C CRYPTO_malloc,memcpy,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_put_error,EVP_CIPHER_CTX_free,EVP_MD_CTX_free, 19_2_6CCA071C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC900C3 CRYPTO_free,CRYPTO_memdup,strcmp,strlen,OPENSSL_cleanse,CRYPTO_memcmp,OPENSSL_cleanse, 19_2_6CC900C3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6C0C8 EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,COMP_expand_block, 19_2_6CC6C0C8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC660F0 CRYPTO_malloc,CRYPTO_free,ERR_put_error, 19_2_6CC660F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC920F3 CRYPTO_free,CRYPTO_memdup, 19_2_6CC920F3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8A0A0 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset, 19_2_6CC8A0A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7A0AB CRYPTO_free,CRYPTO_strdup, 19_2_6CC7A0AB
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAC048 CRYPTO_free,CRYPTO_memdup, 19_2_6CCAC048
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74060 CRYPTO_get_ex_new_index, 19_2_6CC74060
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7A007 CRYPTO_free,CRYPTO_strdup, 19_2_6CC7A007
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA6018 EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA6018
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A1E0 CRYPTO_free, 19_2_6CC6A1E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC661F0 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC661F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9C18C CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 19_2_6CC9C18C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8A144 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset, 19_2_6CC8A144
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6615C CRYPTO_free, 19_2_6CC6615C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC92166 CRYPTO_free,CRYPTO_memdup, 19_2_6CC92166
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAC11C CRYPTO_memdup, 19_2_6CCAC11C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A2E0 CRYPTO_free,CRYPTO_malloc, 19_2_6CC6A2E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC622F6 CRYPTO_zalloc,CRYPTO_free, 19_2_6CC622F6
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC662B4 CRYPTO_free,CRYPTO_free, 19_2_6CC662B4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8A25C CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset, 19_2_6CC8A25C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6625C CRYPTO_free,CRYPTO_free, 19_2_6CC6625C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7427B i2d_X509_NAME,i2d_X509_NAME,CRYPTO_free,CRYPTO_free,memcmp, 19_2_6CC7427B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66203 CRYPTO_free,CRYPTO_free, 19_2_6CC66203
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6A210 CRYPTO_malloc, 19_2_6CC6A210
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8E210 EVP_MD_size,EVP_MD_CTX_new,EVP_DigestInit_ex,EVP_DigestFinal_ex,OPENSSL_cleanse,OPENSSL_cleanse,EVP_PKEY_free,EVP_MD_CTX_free,EVP_DigestInit_ex,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_PKEY_new_raw_private_key,EVP_DigestSignInit,EVP_DigestUpdate,EVP_DigestSignFinal,CRYPTO_memcmp,BIO_ctrl,EVP_DigestUpdate, 19_2_6CC8E210
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA6229 EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA6229
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC743E1 CRYPTO_free,CRYPTO_free,memcmp, 19_2_6CC743E1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA63F8 CRYPTO_free,CRYPTO_malloc,RAND_bytes, 19_2_6CCA63F8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC803A9 CRYPTO_free,CRYPTO_memdup,ERR_put_error, 19_2_6CC803A9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74345 i2d_X509_NAME,i2d_X509_NAME,CRYPTO_free,CRYPTO_free,memcmp, 19_2_6CC74345
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC64340 CRYPTO_free, 19_2_6CC64340
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC66350 CRYPTO_free, 19_2_6CC66350
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7035B CRYPTO_strdup, 19_2_6CC7035B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC62323 CRYPTO_zalloc, 19_2_6CC62323
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC74328 CRYPTO_free,CRYPTO_free, 19_2_6CC74328
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8FC84 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,CRYPTO_free,EVP_PKEY_free, 19_2_6CC8FC84
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7BC94 CRYPTO_THREAD_run_once, 19_2_6CC7BC94
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC83CB8 CRYPTO_free, 19_2_6CC83CB8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7BC50 OPENSSL_init_crypto,CRYPTO_THREAD_run_once,ERR_put_error,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once, 19_2_6CC7BC50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA5C66 EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA5C66
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC89C70 CRYPTO_malloc,CRYPTO_THREAD_lock_new,CRYPTO_new_ex_data,X509_up_ref,X509_chain_up_ref,CRYPTO_strdup,CRYPTO_strdup,CRYPTO_dup_ex_data,CRYPTO_strdup,CRYPTO_memdup,ERR_put_error,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_memdup,ERR_put_error, 19_2_6CC89C70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC83C24 strlen,CRYPTO_free,CRYPTO_strdup,CRYPTO_free,ERR_put_error, 19_2_6CC83C24
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA9D89 OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_num,OPENSSL_sk_value, 19_2_6CCA9D89
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8FDB6 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free, 19_2_6CC8FDB6
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7BD57 CRYPTO_THREAD_run_once, 19_2_6CC7BD57
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7BD24 CRYPTO_THREAD_run_once, 19_2_6CC7BD24
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC83D35 strlen,CRYPTO_free,CRYPTO_strdup,CRYPTO_free,ERR_put_error, 19_2_6CC83D35
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9FE86 CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MD_CTX_free, 19_2_6CC9FE86
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8FEA9 CRYPTO_free, 19_2_6CC8FEA9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA5EA3 CRYPTO_free, 19_2_6CCA5EA3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA5E5C EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA5E5C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC77E60 CRYPTO_THREAD_run_once,OPENSSL_sk_find,OPENSSL_sk_value,EVP_CIPHER_flags,EVP_get_cipherbyname,EVP_enc_null,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname, 19_2_6CC77E60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9FE20 CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MD_CTX_free, 19_2_6CC9FE20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC99FD1 CRYPTO_malloc,memcpy, 19_2_6CC99FD1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC8FFBB CRYPTO_free, 19_2_6CC8FFBB
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC93F4B CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 19_2_6CC93F4B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6BF40 EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,COMP_expand_block,CRYPTO_malloc,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,strncmp,strncmp,strncmp, 19_2_6CC6BF40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCAFF47 HMAC_size,EVP_CIPHER_CTX_iv_length,HMAC_Update,HMAC_Final,CRYPTO_memcmp,EVP_CIPHER_CTX_iv_length,EVP_CIPHER_CTX_iv_length,CRYPTO_malloc,EVP_DecryptUpdate,EVP_DecryptFinal,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,EVP_sha256,HMAC_Init_ex,EVP_aes_256_cbc,EVP_DecryptInit_ex, 19_2_6CCAFF47
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA5F59 EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA5F59
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC99F60 CRYPTO_malloc,memcpy, 19_2_6CC99F60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9BF37 CRYPTO_free,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_memdup,CRYPTO_free, 19_2_6CC9BF37
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA58C5 EVP_MD_CTX_new,strlen,BN_num_bits,BN_bn2bin,EVP_PKEY_size,EVP_DigestSignInit,EVP_DigestSign,CRYPTO_free,EVP_MD_CTX_free,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,BN_num_bits,BN_num_bits,memset,EVP_PKEY_security_bits,CRYPTO_free,EVP_PKEY_new,EVP_PKEY_assign,EVP_PKEY_get1_tls_encodedpoint,DH_free,EVP_PKEY_get0_DH,EVP_PKEY_free,DH_get0_pqg,DH_get0_key,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl, 19_2_6CCA58C5
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC658D0 CRYPTO_free, 19_2_6CC658D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCA18E7 CRYPTO_free,EVP_MD_CTX_free, 19_2_6CCA18E7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC938F9 CRYPTO_free,CRYPTO_memdup, 19_2_6CC938F9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC918F3 CRYPTO_free,CRYPTO_malloc,memcpy,CRYPTO_memdup,memcmp, 19_2_6CC918F3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7D883 ERR_put_error,CRYPTO_realloc,CRYPTO_realloc,memset,ERR_put_error, 19_2_6CC7D883
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC81886 ERR_put_error,CRYPTO_free, 19_2_6CC81886
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9B890 OPENSSL_sk_new_null,X509_free,OPENSSL_sk_pop_free,d2i_X509,CRYPTO_free,OPENSSL_sk_push,ERR_clear_error,OPENSSL_sk_value,X509_get0_pubkey,EVP_PKEY_missing_parameters,X509_free,X509_up_ref,CRYPTO_free, 19_2_6CC9B890
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC89850 OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock, 19_2_6CC89850
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC65860 CRYPTO_zalloc,ERR_put_error, 19_2_6CC65860
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC99864 BN_num_bits,BN_bn2bin,CRYPTO_free,CRYPTO_strdup, 19_2_6CC99864
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7F820 CONF_parse_list,CONF_parse_list,CRYPTO_malloc,memcpy,CRYPTO_free,OPENSSL_LH_num_items, 19_2_6CC7F820
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7B833 CRYPTO_free, 19_2_6CC7B833
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC65830 CRYPTO_free, 19_2_6CC65830
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6F9C0 CRYPTO_clear_free, 19_2_6CC6F9C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC899F1 CRYPTO_THREAD_unlock, 19_2_6CC899F1
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC89999 CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete, 19_2_6CC89999
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA0960 ERR_clear_error,SSL_connect,SSL_version,SSL_get_error,SSL_get_current_cipher,SSL_CIPHER_get_name,SSL_get0_alpn_selected,WSAGetLastError,memset,ERR_get_error,SSL_get_verify_result,ERR_error_string_n,strncpy,memset,BIO_s_mem,BIO_new,SSL_get_peer_cert_chain,OPENSSL_sk_num,BIO_s_mem,BIO_new,BIO_ctrl,BIO_ctrl,PEM_write_bio_X509,BIO_ctrl,BIO_ctrl,OPENSSL_sk_value,X509_get_subject_name,X509_NAME_print_ex,BIO_ctrl,BIO_ctrl,X509_get_issuer_name,X509_NAME_print_ex,BIO_ctrl,BIO_ctrl,X509_get_version,BIO_printf,BIO_ctrl,BIO_ctrl,X509_get_serialNumber,BIO_puts,BIO_printf,BIO_ctrl,BIO_ctrl,X509_get0_signature,i2a_ASN1_OBJECT,BIO_ctrl,BIO_ctrl,X509_get_X509_PUBKEY,X509_PUBKEY_get0_param,i2a_ASN1_OBJECT,BIO_ctrl,BIO_ctrl,X509_get0_extensions,OPENSSL_sk_num,OPENSSL_sk_num,BIO_ctrl,BIO_free,OPENSSL_sk_num,OPENSSL_sk_value,BIO_s_mem,BIO_new,X509_EXTENSION_get_object,i2t_ASN1_OBJECT,X509V3_EXT_print,X509_EXTENSION_get_data,ASN1_STRING_print,X509_get0_notBefore,ASN1_TIME_print,BIO_ctrl,BIO_ctrl,X509_get0_notAfter,ASN1_TIME_print,BIO_ctrl,BIO_ctrl,X509_get_pubkey,EVP_PKEY_id,EVP_PKEY_get0_RSA,RSA_get0_key,BN_num_bits,BIO_printf,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,EVP_PKEY_get0_DSA,DSA_get0_pqg,DSA_get0_key,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,EVP_PKEY_get0_DH,DH_get0_pqg,DH_get0_key,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,curl_msnprintf,BN_print,BIO_ctrl,BIO_ctrl,EVP_PKEY_free,BIO_printf,memcpy,memset,WSAGetLastError,BIO_free,SSL_get_peer_certificate,X509_get_subject_name,BIO_s_mem,BIO_new,X509_NAME_print_ex,BIO_ctrl,memcpy,BIO_free,BIO_free,X509_get0_notBefore,ASN1_TIME_print,BIO_ctrl,BIO_ctrl,X509_get0_notAfter,ASN1_TIME_print,BIO_ctrl,BIO_ctrl,BIO_free,X509_get_ext_d2i,OPENSSL_sk_num,OPENSSL_sk_value,ASN1_STRING_get0_data,ASN1_STRING_length,strlen,memcmp,GENERAL_NAMES_free,X509_get_issuer_name,BIO_s_mem,BIO_new,X509_NAME_print_ex,BIO_ctrl,memcpy,BIO_free,BIO_s_file,BIO_new,X509_get_subject_name,X509_NAME_get_index_by_NID,X509_NAME_get_entry,X509_NAME_ENTRY_get_data,ASN1_STRING_type,ASN1_STRING_length,CRYPTO_malloc,ASN1_STRING_get0_data,memcpy,X509_verify_cert_error_string,curl_msnprintf,BIO_new_mem_buf,PEM_read_bio_X509,X509_check_issued,ERR_get_error,ERR_error_string_n,strncpy,X509_free,ASN1_STRING_to_UTF8,strlen,CRYPTO_free,X509_free,BIO_free,X509_free,X509_free,BIO_free,X509_free,X509_free,BIO_free,X509_free,SSL_get_verify_result,X509_verify_cert_error_string,X509_verify_cert_error_string,SSL_ctrl,d2i_OCSP_RESPONSE,OCSP_response_status,OCSP_response_status_str,OCSP_RESPONSE_free,X509_free,X509_get_X509_PUBKEY,i2d_X509_PUBKEY,X509_get_X509_PUBKEY,i2d_X509_PUBKEY,X509_free,OCSP_response_get1_basic,SSL_get_peer_cert_chain,SSL_CTX_get_cert_store,OCSP_basic_verify,SSL_get_peer_certificate,OPENSSL_sk_num,OPENSSL_sk_value,X509_ 23_2_6CFA0960
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA2AF0 TLS_client_method,SSL_CTX_free,SSL_CTX_new,SSL_CTX_ctrl,SSL_CTX_set_msg_callback,SSL_CTX_ctrl,ERR_peek_error,ERR_error_string_n,strncpy,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_set_options,SSL_CTX_set_next_proto_select_cb,SSL_CTX_set_alpn_protos,BIO_new_mem_buf,BIO_new_mem_buf,SSL_CTX_set_default_passwd_cb_userdata,SSL_CTX_set_default_passwd_cb,d2i_X509_bio,SSL_CTX_use_certificate,d2i_PKCS12_bio,ERR_clear_error,PEM_read_bio_X509_AUX,SSL_CTX_use_certificate,ERR_peek_error,SSL_CTX_ctrl,PEM_read_bio_X509,SSL_CTX_ctrl,X509_free,ENGINE_ctrl,ENGINE_ctrl_cmd,SSL_CTX_use_certificate,X509_free,SSL_CTX_use_certificate_file,BIO_s_file,BIO_new,BIO_ctrl,d2i_PKCS12_bio,BIO_free,PKCS12_PBE_add,PKCS12_parse,PKCS12_free,SSL_CTX_use_certificate,SSL_CTX_use_PrivateKey,SSL_CTX_check_private_key,OPENSSL_sk_num,OPENSSL_sk_pop,SSL_CTX_add_client_CA,SSL_CTX_ctrl,SSL_CTX_use_certificate_chain_file,X509_free,ERR_get_error,ERR_error_string_n,strncpy,X509_free,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,PKCS12_free,ERR_get_error,ERR_error_string_n,strncpy,PEM_read_bio_PrivateKey,BIO_free,d2i_PrivateKey_bio,SSL_CTX_use_PrivateKey,EVP_PKEY_free,X509_free,SSL_CTX_use_PrivateKey_file,SSL_new,SSL_get_certificate,X509_get_pubkey,SSL_get_privatekey,EVP_PKEY_copy_parameters,EVP_PKEY_free,SSL_get_privatekey,EVP_PKEY_id,EVP_PKEY_get1_RSA,RSA_flags,RSA_free,SSL_free,SSL_CTX_check_private_key,SSL_free,ERR_peek_last_error,ERR_clear_error,EVP_PKEY_free,X509_free,OPENSSL_sk_pop_free,UI_create_method,UI_OpenSSL,UI_method_get_opener,UI_method_set_opener,UI_OpenSSL,UI_method_get_closer,UI_method_set_closer,UI_method_set_reader,UI_method_set_writer,ENGINE_load_private_key,UI_destroy_method,SSL_CTX_use_PrivateKey,EVP_PKEY_free,EVP_PKEY_free,X509_free,OPENSSL_sk_pop_free,EVP_PKEY_free,BIO_free,BIO_free,SSL_CTX_set_cipher_list,SSL_CTX_set_ciphersuites,SSL_CTX_set_post_handshake_auth,SSL_CTX_ctrl,SSL_CTX_set_srp_username,SSL_CTX_set_srp_password,SSL_CTX_set_cipher_list,SSL_CTX_get_cert_store,CertOpenSystemStoreW,CompareFileTime,GetLastError,CertEnumCertificatesInStore,GetSystemTimeAsFileTime,CompareFileTime,CompareFileTime,CertGetIntendedKeyUsage,CertGetEnhancedKeyUsage,CertGetEnhancedKeyUsage,strcmp,GetLastError,d2i_X509,X509_STORE_add_cert,X509_free,CompareFileTime,CertFreeCertificateContext,CertCloseStore,SSL_CTX_load_verify_locations,SSL_CTX_get_cert_store,X509_LOOKUP_file,X509_STORE_add_lookup,X509_load_crl_file,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_set_verify,SSL_CTX_set_keylog_callback,SSL_CTX_ctrl,SSL_CTX_sess_set_new_cb,SSL_free,SSL_new,SSL_ctrl,SSL_set_connect_state,SSL_ctrl,CRYPTO_get_ex_new_index,CRYPTO_get_ex_new_index,SSL_set_ex_data,SSL_set_ex_data,SSL_set_session,SSL_set_fd,ERR_get_error,ERR_error_string_n,strncpy,BIO_f_ssl,BIO_ne 23_2_6CFA2AF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA8580 memset,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, 23_2_6CFA8580
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE46E0 EVP_CIPHER_CTX_key_length,EVP_aes_128_ecb,EVP_aes_256_ecb,EVP_aes_192_ecb,malloc,EVP_CIPHER_CTX_new,EVP_EncryptInit,EVP_CIPHER_CTX_set_padding,memcpy,EVP_CIPHER_CTX_set_app_data,EVP_CIPHER_CTX_free,free, 23_2_6CFE46E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA8670 CertGetCertificateChain,GetLastError,CertOpenStore,GetLastError,wcslen,free,CreateFileW,GetFileSizeEx,GetLastError,GetLastError,GetLastError,CloseHandle,free,CertCreateCertificateChainEngine,ReadFile,GetLastError,CertFreeCertificateChainEngine,CertCloseStore,CertFreeCertificateChain,CertFreeCertificateContext,free,strstr,strstr,CryptQueryObject,CertAddCertificateContextToStore,CertFreeCertificateContext,GetLastError,GetLastError,GetLastError, 23_2_6CFA8670
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE47B0 EVP_CIPHER_CTX_get_app_data,EVP_EncryptUpdate, 23_2_6CFE47B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5A100 DES_set_odd_parity,DES_set_key,DES_ecb_encrypt,DES_set_odd_parity,DES_set_key,DES_ecb_encrypt,DES_set_odd_parity,DES_set_key,DES_ecb_encrypt, 23_2_6CF5A100
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5A300 strlen,memset,DES_set_odd_parity,DES_set_key,DES_ecb_encrypt,DES_set_odd_parity,DES_set_key,DES_ecb_encrypt, 23_2_6CF5A300
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF9FF70 OPENSSL_init_ssl,CRYPTO_get_ex_new_index,CRYPTO_get_ex_new_index, 23_2_6CF9FF70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA5850 CryptAcquireContextW,CryptGenRandom,CryptReleaseContext, 23_2_6CFA5850
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA59A0 memcpy,free,memmove,memset,CertFreeCertificateContext,WSAGetLastError,free,strchr,strtol,strchr,strlen,strncpy,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,memcmp,wcschr,wcsncmp,wcsncmp,wcsncmp,wcsncmp,wcsncmp,wcsncmp,wcsncmp,wcsncmp,free,fseek,free,ftell,fseek,CertEnumCertificatesInStore,CertEnumCertificatesInStore,CertEnumCertificatesInStore,fread,fclose,strlen,MultiByteToWideChar,PFXImportCertStore,CertFindCertificateInStore,CertCloseStore,CertFreeCertificateContext,fclose,GetLastError,CertFreeCertificateContext,GetLastError,CertCloseStore,CertFreeCertificateContext,CertEnumCertificatesInStore,CertEnumCertificatesInStore,CertFreeCertificateContext,CertFreeCertificateContext,wcschr,wcslen,CertOpenStore,CryptStringToBinaryW,CertFindCertificateInStore,free,free,GetLastError,free,free,CertCloseStore, 23_2_6CFA59A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA9020 CertGetNameStringW,CertFindExtension,CryptDecodeObjectEx,wcslen, 23_2_6CFA9020
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA52A0 CRYPTO_get_ex_new_index,CRYPTO_get_ex_new_index,SSL_get_ex_data,SSL_get_ex_data, 23_2_6CFA52A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: -----BEGIN PUBLIC KEY----- 23_2_6CFAA600
Source: BackupExtractor.exe Binary or memory string: -----BEGIN PUBLIC KEY-----
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [edi+04h], 424D53FFh 23_2_6CF8CD20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [ebx+04h], 424D53FFh 23_2_6CF8CD20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [edi+04h], 424D53FFh 23_2_6CF8D280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [esi+04h], 424D53FFh 23_2_6CF8D280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [ebx+04h], 424D53FFh 23_2_6CF8D280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [ebx+04h], 424D53FFh 23_2_6CF8D280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [esi+04h], 424D53FFh 23_2_6CF8D280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: mov dword ptr [ebx+04h], 424D53FFh 23_2_6CF8D280
Source: Binary string: D:\software\89.ios-recovery-win-gui-cool-itunes-5.2\projects\gui\Win32\Release\Bin\iOSRecoveryManager.pdb source: BackupExtractor.exe, 00000004.00000000.1265695109.0000000000AFE000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: D:\software\89.ios-recovery-win-gui-cool-itunes-5.2\projects\gui\Win32\Release\Bin\iOSRecoveryManager.pdbFF1 source: BackupExtractor.exe, 00000004.00000000.1265695109.0000000000AFE000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: *.exe|*.dll|*.pdb source: BackupExtractor.exe, 00000004.00000003.1297410205.0000000006EC0000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1297180624.0000000006EC0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: BackupExtractor.exe
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: BackupExtractor.exe
Source: Binary string: "*.exe|*.dll|*.pdbV source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp
Source: C:\Windows\System32\msiexec.exe File opened: z: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: x: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: v: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: t: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: r: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: p: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: n: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: l: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: j: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: h: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: f: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: b: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: y: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: w: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: u: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: s: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: q: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: o: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: m: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: k: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: i: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: g: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: e: Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: c: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: a: Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AC5540 memset,FindFirstFileW,_invalid_parameter_noinfo_noreturn,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?FindIfMatchW@Utils@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@PB_W0@Z,?IsFileExist@BASUtilityFile@@SA_NPB_W@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?CompareVersion@BASUtilityString@@SAHPBD0@Z,SimpleUString::operator=,?Free@BASUtilityString@@SAXPAX@Z,?Free@BASUtilityString@@SAXPAX@Z,?Free@BASUtilityString@@SAXPAX@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn, 19_2_00AC5540
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AB6910 pthread_once,PathFindFileNameW,memmove,FindFirstFileW,_invalid_parameter_noinfo_noreturn,memcpy,_waccess,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?CompareVersion@BASUtilityString@@SAHPBD0@Z,?Free@BASUtilityString@@SAXPAX@Z,FindNextFileW,FindClose,?ConvertUtf8ToUnicode@BASUtilityString@@SAPA_WPBD@Z,_wfopen,fseek,fseek,ftell,fseek,malloc,memset,fread,??0LogMessage@google@@QAE@PBDHH@Z,?stream@LogMessage@google@@QAEAAV?$basic_ostream@DU?$char_traits@D@std@@@std@@XZ,??1LogMessage@google@@QAE@XZ,?ConvertUtf8ToUnicode@BASUtilityString@@SAPA_WPBD@Z,_waccess,SetDllDirectoryW,SetDllDirectoryW,LoadLibraryW,SetDllDirectoryW,GetProcAddress,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?Free@BASUtilityString@@SAXPAX@Z,malloc,pthread_mutex_lock,pthread_mutex_unlock, 19_2_00AB6910
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD3F60 memset,wcscpy_s,wcscat_s,FindFirstFileW,StrStrIW,StrStrIW,DeleteFileW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn, 19_2_00AD3F60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push ebx 23_2_6CFD6C70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push ebx 23_2_6CFDCDF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ebx, dword ptr [edi+4Ch] 23_2_6CFCAD80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then test eax, eax 23_2_6CFB8D70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then test ebx, ebx 23_2_6CFB8D70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ecx, dword ptr [edi+0Ch] 23_2_6CFBEE80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp eax, 04h 23_2_6CFFAE20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov eax, esi 23_2_6CFECFD0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov dword ptr [esp], 00000000h 23_2_6CF74FB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then test eax, eax 23_2_6D000E60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push 0000000Bh 23_2_6CF568C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov dword ptr [esi+58h], edx 23_2_6CFC6880
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov dword ptr [edx], ecx 23_2_6CFFA990
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then shr ecx, 07h 23_2_6CFC0A20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then lea eax, dword ptr [esp+28h] 23_2_6CF56BC0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov eax, dword ptr [ebp+0000CEA0h] 23_2_6CFDCB50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov dword ptr [ebp+0000CEA0h], 00000000h 23_2_6CFDCB50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push esi 23_2_6CFDA4D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push ebx 23_2_6CFD8480
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp eax, FFFFFFDBh 23_2_6CFDE420
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then inc ebp 23_2_6CFB85B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov byte ptr [ebp+00h], cl 23_2_6CF86570
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ecx, dword ptr [ebx+0000CB64h] 23_2_6CFD66D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push dword ptr [eax+edx*4-04h] 23_2_6CF70650
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp ecx, esi 23_2_6CFE67C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then test edi, edi 23_2_6CFD675B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then movzx ecx, byte ptr [ebx] 23_2_6CF9C030
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp byte ptr [ebp+000000AAh], 00000000h 23_2_6CFC6230
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ebx, dword ptr [esi] 23_2_6CF6A200
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then test esi, esi 23_2_6CF563D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp byte ptr [eax], 00000020h 23_2_6CF79CB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then xor ebx, ebx 23_2_6CF79CB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ebx, esi 23_2_6CF53D30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ebx, esi 23_2_6CF53ED3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ebp, dword ptr [ebp+00h] 23_2_6CF57E40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push 00000000h 23_2_6CF5FFA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov edi, dword ptr [esp+00000340h] 23_2_6CF87850
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then push edi 23_2_6CFD74C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov eax, dword ptr [esi] 23_2_6CFC3420
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then shl ebx, 08h 23_2_6CF9B550
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov esi, dword ptr [ebx+edx-04h] 23_2_6CFF5540
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov edx, dword ptr [ebp+esi-04h] 23_2_6CFF5540
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov ecx, dword ptr [edx] 23_2_6CFC3750
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then movzx eax, byte ptr [esp+esi+000001B7h] 23_2_6CF7B1D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then mov edi, dword ptr [esp+04h] 23_2_6CF83160
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp word ptr [ecx+eax*2-22h], FFFFh 23_2_6D003280
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 4x nop then cmp edi, 00000100h 23_2_6D003280
Source: global traffic TCP traffic: 192.168.2.7:49727 -> 8.8.8.8:53
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 65.38.121.69
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 146.19.254.194
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: unknown TCP traffic detected without corresponding DNS query: 192.121.22.224
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7E880 recv,recv,recv, 23_2_6CF7E880
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://.css
Source: BackupExtractor.exe String found in binary or memory: http://.jpg
Source: BackupExtractor.exe String found in binary or memory: http://html4/loose.dtd
Source: BackupExtractor.exe String found in binary or memory: http://www.brynosaurus.com/cachedir/
Source: BackupExtractor.exe, 00000004.00000003.1592953238.000000007E5C0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1594280396.000000007FA70000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592097219.000000007E860000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1593520884.000000007EA60000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1594197654.000000007F9B0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592322911.000000007EC30000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1593451609.000000007E940000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.openssl.org/V
Source: BackupExtractor.exe, 00000004.00000003.1592953238.000000007E5C0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1594280396.000000007FA70000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1591484950.000000007EBB0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592097219.000000007E860000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592322911.000000007EC30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.openssl.org/support/faq.html
Source: BackupExtractor.exe, 00000004.00000003.1592953238.000000007E5C0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1594280396.000000007FA70000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1591484950.000000007EBB0000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592097219.000000007E860000.00000004.00001000.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1592322911.000000007EC30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.openssl.org/support/faq.htmlRAND
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/alt-svc.html
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/alt-svc.html#
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/hsts.html
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/hsts.html#
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/http-cookies.html
Source: BackupExtractor.exe String found in binary or memory: https://curl.se/docs/http-cookies.html#
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745

E-Banking Fraud

barindex
Source: Yara match File source: 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1308078998.0000000009501000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1293571064.0000000008435000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1305389223.0000000009500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1301409791.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: BackupExtractor.exe PID: 5328, type: MEMORYSTR
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA8670 CertGetCertificateChain,GetLastError,CertOpenStore,GetLastError,wcslen,free,CreateFileW,GetFileSizeEx,GetLastError,GetLastError,GetLastError,CloseHandle,free,CertCreateCertificateChainEngine,ReadFile,GetLastError,CertFreeCertificateChainEngine,CertCloseStore,CertFreeCertificateChain,CertFreeCertificateContext,free,strstr,strstr,CryptQueryObject,CertAddCertificateContextToStore,CertFreeCertificateContext,GetLastError,GetLastError,GetLastError, 23_2_6CFA8670

System Summary

barindex
Source: iconv.dll.2.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process Stats: CPU usage > 49%
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\4c320a.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{58F90A35-6245-4CD8-953C-458660066C65} Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI3566.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\4c320c.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\4c320c.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\4c320c.msi Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD22D0 19_2_00AD22D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF05E0 19_2_00AF05E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD26D0 19_2_00AD26D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD4740 19_2_00AD4740
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AB6910 19_2_00AB6910
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00ACB940 19_2_00ACB940
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD0BB0 19_2_00AD0BB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AC7FF0 19_2_00AC7FF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6248D2D4 19_2_6248D2D4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_624868CC 19_2_624868CC
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E81A7C 19_2_62E81A7C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E83A1C 19_2_62E83A1C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E8B0B0 19_2_62E8B0B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E8F7E0 19_2_62E8F7E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E81794 19_2_62E81794
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E87F24 19_2_62E87F24
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E934C4 19_2_62E934C4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E86D4C 19_2_62E86D4C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E89D51 19_2_62E89D51
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78CD9 19_2_6CC78CD9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC88F80 19_2_6CC88F80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9EA89 19_2_6CC9EA89
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78AA4 19_2_6CC78AA4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78B36 19_2_6CC78B36
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC78440 19_2_6CC78440
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC7850C 19_2_6CC7850C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6E533 19_2_6CC6E533
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCBA700 19_2_6CCBA700
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6E158 19_2_6CC6E158
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6E3C0 19_2_6CC6E3C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6BDE9 19_2_6CC6BDE9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6BDB0 19_2_6CC6BDB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC9B890 19_2_6CC9B890
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CC6D990 19_2_6CC6D990
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF8C50 23_2_6CFF8C50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF6ED80 23_2_6CF6ED80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D002C90 23_2_6D002C90
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFC0E70 23_2_6CFC0E70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFFAE20 23_2_6CFFAE20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D000E60 23_2_6D000E60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFBEF90 23_2_6CFBEF90
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF84F70 23_2_6CF84F70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFFEF70 23_2_6CFFEF70
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF6F00 23_2_6CFF6F00
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7E880 23_2_6CF7E880
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D00E9F0 23_2_6D00E9F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFB0800 23_2_6CFB0800
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFD09F0 23_2_6CFD09F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA0960 23_2_6CFA0960
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFEE950 23_2_6CFEE950
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA2AF0 23_2_6CFA2AF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D00AB40 23_2_6D00AB40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF52AB0 23_2_6CF52AB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF56BC0 23_2_6CF56BC0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFB0BAD 23_2_6CFB0BAD
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF2B30 23_2_6CFF2B30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7CB10 23_2_6CF7CB10
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFEC5B0 23_2_6CFEC5B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF2570 23_2_6CFF2570
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA8670 23_2_6CFA8670
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D0107B0 23_2_6D0107B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF867C0 23_2_6CF867C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF88790 23_2_6CF88790
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFFE780 23_2_6CFFE780
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D002680 23_2_6D002680
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF6090 23_2_6CFF6090
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D000170 23_2_6D000170
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE8080 23_2_6CFE8080
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF9C030 23_2_6CF9C030
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF60180 23_2_6CF60180
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D002090 23_2_6D002090
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF2150 23_2_6CFF2150
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFC2130 23_2_6CFC2130
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5A100 23_2_6CF5A100
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF63D0 23_2_6CFF63D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7A3A0 23_2_6CF7A3A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D0022D0 23_2_6D0022D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5A300 23_2_6CF5A300
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFFFC50 23_2_6CFFFC50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF83DB0 23_2_6CF83DB0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFCBD50 23_2_6CFCBD50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFEDD50 23_2_6CFEDD50
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF53D30 23_2_6CF53D30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF7E30 23_2_6CFF7E30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D00BE00 23_2_6D00BE00
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFB3F40 23_2_6CFB3F40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE7F40 23_2_6CFE7F40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFB9F20 23_2_6CFB9F20
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF818F0 23_2_6CF818F0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF6B850 23_2_6CF6B850
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF87850 23_2_6CF87850
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF77820 23_2_6CF77820
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFCF9D4 23_2_6CFCF9D4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA59A0 23_2_6CFA59A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF9990 23_2_6CFF9990
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFCD970 23_2_6CFCD970
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5D930 23_2_6CF5D930
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE7AE0 23_2_6CFE7AE0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D005B80 23_2_6D005B80
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE9A30 23_2_6CFE9A30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFBFB30 23_2_6CFBFB30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF594B0 23_2_6CF594B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE7440 23_2_6CFE7440
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF77410 23_2_6CF77410
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF6558B 23_2_6CF6558B
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFD7570 23_2_6CFD7570
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF9B550 23_2_6CF9B550
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFF9620 23_2_6CFF9620
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7F74F 23_2_6CF7F74F
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFEF0C0 23_2_6CFEF0C0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFE70B0 23_2_6CFE70B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF5F000 23_2_6CF5F000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D005010 23_2_6D005010
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF7B1D0 23_2_6CF7B1D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF972E0 23_2_6CF972E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFFB240 23_2_6CFFB240
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF713B0 23_2_6CF713B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF993B0 23_2_6CF993B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF933A0 23_2_6CF933A0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF92300 appears 45 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF92650 appears 35 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF82520 appears 51 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 00AB7DA0 appears 41 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6D011A48 appears 79 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6D0119E0 appears 38 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CFD3530 appears 183 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF7C800 appears 47 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF87E10 appears 496 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF96C90 appears 31 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6D011A00 appears 51 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 00AB6560 appears 41 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF7C680 appears 58 times
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: String function: 6CF87C70 appears 433 times
Source: libHelper.dll.2.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: libView.dll.2.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: zlib1.dll.2.dr Static PE information: Number of sections : 11 > 10
Source: libcrypto-1_1.dll.2.dr Static PE information: Number of sections : 11 > 10
Source: libssl-1_1.dll.2.dr Static PE information: Number of sections : 11 > 10
Source: pthreadGC2.dll.2.dr Static PE information: Number of sections : 21 > 10
Source: libxml2-2.dll.2.dr Static PE information: Number of sections : 19 > 10
Source: libcurl.dll.2.dr Static PE information: Number of sections : 11 > 10
Source: classification engine Classification label: mal96.phis.bank.troj.spyw.evad.winMSI@11/116@0/4
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF92BE0 GetLastError,_errno,curl_msnprintf,curl_msnprintf,FormatMessageW,wcstombs,strchr,curl_msnprintf,_errno,_errno,GetLastError,SetLastError, 23_2_6CF92BE0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA2AF0 TLS_client_method,SSL_CTX_free,SSL_CTX_new,SSL_CTX_ctrl,SSL_CTX_set_msg_callback,SSL_CTX_ctrl,ERR_peek_error,ERR_error_string_n,strncpy,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_ctrl,SSL_CTX_set_options,SSL_CTX_set_next_proto_select_cb,SSL_CTX_set_alpn_protos,BIO_new_mem_buf,BIO_new_mem_buf,SSL_CTX_set_default_passwd_cb_userdata,SSL_CTX_set_default_passwd_cb,d2i_X509_bio,SSL_CTX_use_certificate,d2i_PKCS12_bio,ERR_clear_error,PEM_read_bio_X509_AUX,SSL_CTX_use_certificate,ERR_peek_error,SSL_CTX_ctrl,PEM_read_bio_X509,SSL_CTX_ctrl,X509_free,ENGINE_ctrl,ENGINE_ctrl_cmd,SSL_CTX_use_certificate,X509_free,SSL_CTX_use_certificate_file,BIO_s_file,BIO_new,BIO_ctrl,d2i_PKCS12_bio,BIO_free,PKCS12_PBE_add,PKCS12_parse,PKCS12_free,SSL_CTX_use_certificate,SSL_CTX_use_PrivateKey,SSL_CTX_check_private_key,OPENSSL_sk_num,OPENSSL_sk_pop,SSL_CTX_add_client_CA,SSL_CTX_ctrl,SSL_CTX_use_certificate_chain_file,X509_free,ERR_get_error,ERR_error_string_n,strncpy,X509_free,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,ERR_get_error,ERR_error_string_n,strncpy,PKCS12_free,ERR_get_error,ERR_error_string_n,strncpy,PEM_read_bio_PrivateKey,BIO_free,d2i_PrivateKey_bio,SSL_CTX_use_PrivateKey,EVP_PKEY_free,X509_free,SSL_CTX_use_PrivateKey_file,SSL_new,SSL_get_certificate,X509_get_pubkey,SSL_get_privatekey,EVP_PKEY_copy_parameters,EVP_PKEY_free,SSL_get_privatekey,EVP_PKEY_id,EVP_PKEY_get1_RSA,RSA_flags,RSA_free,SSL_free,SSL_CTX_check_private_key,SSL_free,ERR_peek_last_error,ERR_clear_error,EVP_PKEY_free,X509_free,OPENSSL_sk_pop_free,UI_create_method,UI_OpenSSL,UI_method_get_opener,UI_method_set_opener,UI_OpenSSL,UI_method_get_closer,UI_method_set_closer,UI_method_set_reader,UI_method_set_writer,ENGINE_load_private_key,UI_destroy_method,SSL_CTX_use_PrivateKey,EVP_PKEY_free,EVP_PKEY_free,X509_free,OPENSSL_sk_pop_free,EVP_PKEY_free,BIO_free,BIO_free,SSL_CTX_set_cipher_list,SSL_CTX_set_ciphersuites,SSL_CTX_set_post_handshake_auth,SSL_CTX_ctrl,SSL_CTX_set_srp_username,SSL_CTX_set_srp_password,SSL_CTX_set_cipher_list,SSL_CTX_get_cert_store,CertOpenSystemStoreW,CompareFileTime,GetLastError,CertEnumCertificatesInStore,GetSystemTimeAsFileTime,CompareFileTime,CompareFileTime,CertGetIntendedKeyUsage,CertGetEnhancedKeyUsage,CertGetEnhancedKeyUsage,strcmp,GetLastError,d2i_X509,X509_STORE_add_cert,X509_free,CompareFileTime,CertFreeCertificateContext,CertCloseStore,SSL_CTX_load_verify_locations,SSL_CTX_get_cert_store,X509_LOOKUP_file,X509_STORE_add_lookup,X509_load_crl_file,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_get_cert_store,X509_STORE_set_flags,SSL_CTX_set_verify,SSL_CTX_set_keylog_callback,SSL_CTX_ctrl,SSL_CTX_sess_set_new_cb,SSL_free,SSL_new,SSL_ctrl,SSL_set_connect_state,SSL_ctrl,CRYPTO_get_ex_new_index,CRYPTO_get_ex_new_index,SSL_set_ex_data,SSL_set_ex_data,SSL_set_session,SSL_set_fd,ERR_get_error,ERR_error_string_n,strncpy,BIO_f_ssl,BIO_ne 23_2_6CFA2AF0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00ACA120 CreateToolhelp32Snapshot,memset,tolower,Process32FirstW,OpenProcess,EnumProcessModules,memset,GetModuleFileNameExW,CloseHandle,tolower,Process32NextW,CloseHandle,OpenProcess,TerminateProcess,WaitForSingleObject,_invalid_parameter_noinfo_noreturn, 19_2_00ACA120
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00ACB870 CoCreateInstance, 19_2_00ACB870
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD34A0 LoadLibraryExW,LoadLibraryExW,LoadLibraryExW,FindResourceW,LoadResource,SizeofResource,MultiByteToWideChar,FreeLibrary, 19_2_00AD34A0
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Roaming\Microsoft\CML35A4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Mutant created: \Sessions\1\BaseNamedObjects\Global_Coolmuster iPhone Backup Extractor_3.5.11
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Mutant created: \Sessions\1\BaseNamedObjects\62107868
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1876:120:WilError_03
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\TEMP\~DF6F5C6E2DAFBE1548.TMP Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: %Y%m%d 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: %Y%m%d%H%M%S 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: .dmp 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: %Y%m%d 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: %Y%m%d%H%M%S 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Command line argument: .dmp 19_2_00ADB000
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\msiexec.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: AdvancedReclaiMeFreeRAIDRecoveryFreeSetup.msi Static file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: BackupExtractor.exe String found in binary or memory: set-addPolicy
Source: BackupExtractor.exe String found in binary or memory: id-cmc-addExtensions
Source: BackupExtractor.exe String found in binary or memory: t xml:space=.gif" border="0"</body> </html> overflow:hidden;img src="http://addEventListenerresponsible for s.js"></script> /favicon.ico" />operating system" style="width:1target="_blank">State Universitytext-align:left; document.write(, including the around t
Source: BackupExtractor.exe String found in binary or memory: Unable to complete request for channel-process-startup
Source: unknown Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\AdvancedReclaiMeFreeRAIDRecoveryFreeSetup.msi"
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: C:\Windows\System32\msiexec.exe Process created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptnet.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: webio.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msihnd.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: spp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libbasic.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: zlib1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: librg.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libi18n.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libglog.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: groceryc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libmodel.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libview.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libxml2-2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libupdate.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libexpat.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcurl.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcrypto-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libssl-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libhelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: quserex.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: activitytraceshelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: iconv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: atlthunk.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wshunix.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: cryptui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: avifil32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvfw32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pstorec.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: ieframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: mlang.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vaultcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: wlanapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: netprofm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: npmproxy.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: mmdevapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: audioses.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libbasic.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: librg.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libi18n.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libglog.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: groceryc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libview.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libxml2-2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libupdate.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libhelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: zlib1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libmodel.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libexpat.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcurl.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: zlib1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcrypto-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libssl-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: quserex.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libbasic.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: librg.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libi18n.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libglog.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: zlib1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: pthreadgc2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: groceryc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libview.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libxml2-2.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libupdate.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libhelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libmodel.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libexpat.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcurl.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: zlib1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libcrypto-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: libssl-1_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: quserex.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: AdvancedReclaiMeFreeRAIDRecoveryFreeSetup.msi Static file information: File size 17424384 > 1048576
Source: Binary string: D:\software\89.ios-recovery-win-gui-cool-itunes-5.2\projects\gui\Win32\Release\Bin\iOSRecoveryManager.pdb source: BackupExtractor.exe, 00000004.00000000.1265695109.0000000000AFE000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: D:\software\89.ios-recovery-win-gui-cool-itunes-5.2\projects\gui\Win32\Release\Bin\iOSRecoveryManager.pdbFF1 source: BackupExtractor.exe, 00000004.00000000.1265695109.0000000000AFE000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: *.exe|*.dll|*.pdb source: BackupExtractor.exe, 00000004.00000003.1297410205.0000000006EC0000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1297180624.0000000006EC0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: BackupExtractor.exe
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: BackupExtractor.exe
Source: Binary string: "*.exe|*.dll|*.pdbV source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp
Source: ucrtbase.dll.2.dr Static PE information: 0x82DE8CA7 [Sat Jul 30 07:17:59 2039 UTC]
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD26D0 LoadLibraryW,GetProcAddress,FreeLibrary,memset,SendMessageW,SendMessageW,SendMessageW,SendMessageW,CreatePopupMenu,GetClientRect,SendMessageW,SendMessageW,GetMenuItemCount,memset,memset,GetMenuItemInfoW,memset,SendMessageW,lstrlenW,LoadStringW,AppendMenuW,GetMenuItemCount,DestroyMenu,MessageBeep, 19_2_00AD26D0
Source: groceryc.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x5ffa5
Source: libUpdate.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x12584
Source: libView.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x429c3
Source: libHelper.dll.2.dr Static PE information: real checksum: 0x0 should be: 0xa502
Source: iconv.dll.2.dr Static PE information: real checksum: 0xe26d3 should be: 0xea6d3
Source: libglog.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x31892
Source: libBasic.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x477e7
Source: libI18n.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x8c9e
Source: libRG.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x14e23
Source: ActivityTracesHelper.dll.2.dr Static PE information: real checksum: 0x0 should be: 0x4c56eb
Source: zlib1.dll.2.dr Static PE information: section name: /4
Source: libcrypto-1_1.dll.2.dr Static PE information: section name: /4
Source: libcurl.dll.2.dr Static PE information: section name: .eh_fram
Source: libssl-1_1.dll.2.dr Static PE information: section name: /4
Source: libxml2-2.dll.2.dr Static PE information: section name: /4
Source: libxml2-2.dll.2.dr Static PE information: section name: /14
Source: libxml2-2.dll.2.dr Static PE information: section name: /29
Source: libxml2-2.dll.2.dr Static PE information: section name: /45
Source: libxml2-2.dll.2.dr Static PE information: section name: /57
Source: libxml2-2.dll.2.dr Static PE information: section name: /71
Source: libxml2-2.dll.2.dr Static PE information: section name: /83
Source: libxml2-2.dll.2.dr Static PE information: section name: /96
Source: libxml2-2.dll.2.dr Static PE information: section name: /107
Source: libxml2-2.dll.2.dr Static PE information: section name: /118
Source: pthreadGC2.dll.2.dr Static PE information: section name: /4
Source: pthreadGC2.dll.2.dr Static PE information: section name: /14
Source: pthreadGC2.dll.2.dr Static PE information: section name: /29
Source: pthreadGC2.dll.2.dr Static PE information: section name: /45
Source: pthreadGC2.dll.2.dr Static PE information: section name: /61
Source: pthreadGC2.dll.2.dr Static PE information: section name: /73
Source: pthreadGC2.dll.2.dr Static PE information: section name: /87
Source: pthreadGC2.dll.2.dr Static PE information: section name: /99
Source: pthreadGC2.dll.2.dr Static PE information: section name: /112
Source: pthreadGC2.dll.2.dr Static PE information: section name: /123
Source: pthreadGC2.dll.2.dr Static PE information: section name: /134
Source: msvcp140.dll.2.dr Static PE information: section name: .didat
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFACD6 push ecx; ret 19_2_00AFACE9
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF3E30 push ecx; mov dword ptr [esp], 3F800000h 19_2_00AF40CB
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF3E30 push ecx; mov dword ptr [esp], 3F800000h 19_2_00AF4114
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF3E30 push ecx; mov dword ptr [esp], 3F800000h 19_2_00AF418F
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_624844D0 push eax; mov dword ptr [esp], edi 19_2_624846EF
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_624A1294 push edx; ret 19_2_624A12C7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6248B03C push esi; mov dword ptr [esp], edi 19_2_6248B23D
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6248B03C push eax; mov dword ptr [esp], ebp 19_2_6248B39C
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_624910BB push 41100E0Ah; ret 19_2_624910D8
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6248B674 push eax; mov dword ptr [esp], ebp 19_2_6248BA2A
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62488ACC push eax; mov dword ptr [esp], ebp 19_2_62488C03
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6248BB1C push ebx; mov dword ptr [esp], ebp 19_2_6248BC42
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62481828 push eax; mov dword ptr [esp], 00000000h 19_2_624819E3
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62484FD8 push edx; mov dword ptr [esp], esi 19_2_62484FF7
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62487DB0 push eax; mov dword ptr [esp], edi 19_2_62487E0D
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E962DE push cs; iretd 19_2_62E962B2
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E961DC push cs; iretd 19_2_62E962B2
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E9648E push ebx; ret 19_2_62E9648F
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_62E935D4 push eax; ret 19_2_62E93604
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_6CCC4ED8 pushad ; retf 19_2_6CCC4F12
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D004FB0 push dword ptr [eax+04h]; ret 23_2_6D004FDF
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA0780 push eax; mov dword ptr [esp], 00000000h 23_2_6CFA0785
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA0710 push eax; mov dword ptr [esp], 00000000h 23_2_6CFA0715
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D001C80 push eax; mov dword ptr [esp], edx 23_2_6D001C85
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CFA5850 push eax; mov dword ptr [esp], 00000000h 23_2_6CFA5852
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D096E05 push ecx; ret 23_2_6D096E18
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libssl-1_1.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libBasic.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\ucrtbase.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libUpdate.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\pthreadGC2.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_2.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libI18n.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\iconv.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libHelper.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_atomic_wait.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libglog.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\vcruntime140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_1.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libcrypto-1_1.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\ActivityTracesHelper.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\groceryc.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libmodel.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libView.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\vccorlib140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libRG.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\concrt140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libxml2-2.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_codecvt_ids.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libexpat.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\zlib1.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\libcurl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run Image AutoEnhancer Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run Image AutoEnhancer Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: torConnect
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapter
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk\Enum name: 0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Window / User API: threadDelayed 593 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Window / User API: threadDelayed 664 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Window / User API: threadDelayed 4001 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Window / User API: threadDelayed 3405 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 7547 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1381 Jump to behavior
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_2.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\vccorlib140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\concrt140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_atomic_wait.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_codecvt_ids.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\msvcp140_1.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe API coverage: 0.4 %
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe API coverage: 0.0 %
Source: C:\Windows\System32\msiexec.exe TID: 6552 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 8060 Thread sleep time: -8002000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 8068 Thread sleep time: -75075s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 8064 Thread sleep time: -6810000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 8064 Thread sleep time: -90000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 7976 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe TID: 8000 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1532 Thread sleep count: 7547 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1532 Thread sleep count: 1381 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2184 Thread sleep time: -4611686018427385s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2332 Thread sleep time: -1844674407370954s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AC5540 memset,FindFirstFileW,_invalid_parameter_noinfo_noreturn,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?FindIfMatchW@Utils@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@PB_W0@Z,?IsFileExist@BASUtilityFile@@SA_NPB_W@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?CompareVersion@BASUtilityString@@SAHPBD0@Z,SimpleUString::operator=,?Free@BASUtilityString@@SAXPAX@Z,?Free@BASUtilityString@@SAXPAX@Z,?Free@BASUtilityString@@SAXPAX@Z,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn, 19_2_00AC5540
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AB6910 pthread_once,PathFindFileNameW,memmove,FindFirstFileW,_invalid_parameter_noinfo_noreturn,memcpy,_waccess,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?CompareVersion@BASUtilityString@@SAHPBD0@Z,?Free@BASUtilityString@@SAXPAX@Z,FindNextFileW,FindClose,?ConvertUtf8ToUnicode@BASUtilityString@@SAPA_WPBD@Z,_wfopen,fseek,fseek,ftell,fseek,malloc,memset,fread,??0LogMessage@google@@QAE@PBDHH@Z,?stream@LogMessage@google@@QAEAAV?$basic_ostream@DU?$char_traits@D@std@@@std@@XZ,??1LogMessage@google@@QAE@XZ,?ConvertUtf8ToUnicode@BASUtilityString@@SAPA_WPBD@Z,_waccess,SetDllDirectoryW,SetDllDirectoryW,LoadLibraryW,SetDllDirectoryW,GetProcAddress,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?Free@BASUtilityString@@SAXPAX@Z,malloc,pthread_mutex_lock,pthread_mutex_unlock, 19_2_00AB6910
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD3F60 memset,wcscpy_s,wcscat_s,FindFirstFileW,StrStrIW,StrStrIW,DeleteFileW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn, 19_2_00AD3F60
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Thread delayed: delay time: 75075 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: BackupExtractor.exe, 00000004.00000003.1269021638.0000000000F46000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1296068006.0000000000F45000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll<
Source: C:\Windows\System32\msiexec.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFAA40 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 19_2_00AFAA40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD26D0 LoadLibraryW,GetProcAddress,FreeLibrary,memset,SendMessageW,SendMessageW,SendMessageW,SendMessageW,CreatePopupMenu,GetClientRect,SendMessageW,SendMessageW,GetMenuItemCount,memset,memset,GetMenuItemInfoW,memset,SendMessageW,lstrlenW,LoadStringW,AppendMenuW,GetMenuItemCount,DestroyMenu,MessageBeep, 19_2_00AD26D0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF86FB mov esi, dword ptr fs:[00000030h] 19_2_00AF86FB
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AF85E5 GetProcessHeap,HeapAlloc,InterlockedPopEntrySList,memset,VirtualAlloc,RaiseException,InterlockedPopEntrySList,VirtualFree,InterlockedPushEntrySList, 19_2_00AF85E5
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process created: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFA406 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 19_2_00AFA406
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFAA40 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 19_2_00AFAA40
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFABD6 SetUnhandledExceptionFilter, 19_2_00AFABD6

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe"
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AC51B0 GetVersionExA,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,CloseHandle, 19_2_00AC51B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe" Jump to behavior
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Shell_TrayWndTrayNotifyWndSysPagerToolbarWindow32U
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, BackupExtractor.exe, 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: explorer.exeShell_TrayWnd
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFA782 cpuid 19_2_00AFA782
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion InstallDate Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion ProductId Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion ProductId Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AFA919 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 19_2_00AFA919
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6D0053E0 GetTimeZoneInformation,GetSystemTimeAsFileTime, 23_2_6D0053E0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 19_2_00AD0090 malloc,malloc,malloc,??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IAE@XZ,??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QAE@PAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z,??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IAE@XZ,GetVersionExW,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@K@Z,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@K@Z,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@K@Z,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@G@Z,??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@G@Z,_invalid_parameter_noinfo_noreturn,?ConvertUnicodeToUtf8@BASUtilityString@@SAPADPB_W@Z,?AddJsonDictStringValue@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD2@Z,?AddJsonDictStringValue@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD2@Z,?AddJsonDictStringValue@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD2@Z,?AddJsonDictStringValue@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD2@Z,?AddJsonDictStringValue@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD2@Z,GlobalMemoryStatusEx,?AddJsonDictUInt64Value@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD_K@Z,?AddJsonDictUInt64Value@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD_K@Z,?AddJsonDictUInt64Value@AssJsonUtil@@SAXAAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@AAV?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@3@PBD_K@Z,?ToString@AssJsonUtil@@SA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAV?$GenericValue@U?$UTF8@D@rapidjson@@V?$MemoryPoolAllocator@VCrtAllocator@rapidjson@@@2@@rapidjson@@@Z,?Free@BASUtilityString@@SAXPAX@Z,??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UAE@XZ,??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ,_invalid_parameter_noinfo_noreturn, 19_2_00AD0090
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1308078998.0000000009501000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1293571064.0000000008435000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1305389223.0000000009500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1301409791.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: BackupExtractor.exe PID: 5328, type: MEMORYSTR
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: *electrum*
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: <%appdata%\ElectronCash\wallets
Source: BackupExtractor.exe, 00000004.00000003.1296558041.0000000002ED0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: %appdata%\com.liberty.jaxx\IndexedDB
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: <%appdata%\Exodus\exodus.wallet9
Source: BackupExtractor.exe, 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: *Exodus*
Source: BackupExtractor.exe, 00000004.00000003.1295439567.0000000002EF0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: %localappdata%\Coinomi\Coinomi\wallets=Y
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe File opened: C:\Users\user\AppData\Roaming\Miranda\ Jump to behavior
Source: Yara match File source: 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1308078998.0000000009501000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1293571064.0000000008435000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1305389223.0000000009500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1301409791.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: BackupExtractor.exe PID: 5328, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: 00000004.00000003.1295035414.0000000007E84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1299209569.0000000008420000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1307529167.0000000008F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1308078998.0000000009501000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306813816.000000000950F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1300004753.0000000008F69000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1304480916.0000000008F67000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1303682934.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1294114246.00000000089DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1310985722.0000000009AAC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1306280910.0000000008F65000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1298422223.0000000008F8B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1302926420.0000000008F61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1293571064.0000000008435000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1305389223.0000000009500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000003.1301409791.000000000950D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: BackupExtractor.exe PID: 5328, type: MEMORYSTR
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF628B0 strlen,strchr,getsockname,WSAGetLastError,WSAGetLastError,strchr,strcpy,strncpy,strchr,strtoul,strchr,strtoul,memcpy,htons,bind,WSAGetLastError,getsockname,getsockname,WSAGetLastError,listen,WSAGetLastError,htons,htons,curl_easy_strerror,curl_msnprintf,curl_easy_strerror, 23_2_6CF628B0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF54A30 setsockopt,WSAGetLastError,setsockopt,WSAIoctl,WSAGetLastError,_errno,_errno,_errno,strlen,memset,strncmp,strncmp,htons,htons,strchr,htons,htons,atoi,bind,htons,bind,getsockname,WSAGetLastError,connect,WSAGetLastError,WSAGetLastError, 23_2_6CF54A30
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF78490 ldap_simple_bind_sW,free,free,ldap_bind_sW,ldap_bind_sW, 23_2_6CF78490
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF8FDA0 socket,htonl,setsockopt,bind,getsockname,listen,socket,connect,accept,curl_msnprintf,strlen,send,recv,memcmp,closesocket,closesocket,closesocket,closesocket, 23_2_6CF8FDA0
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF77820 free,strchr,strchr,strchr,free,strchr,strchr,ldap_set_optionW,ldap_initW,ldap_err2stringA,ldap_msgfree,ldap_unbind_s,free,ldap_sslinitW,ldap_set_optionW,ldap_set_optionW,ldap_set_optionW,ldap_err2stringA,ldap_search_sW,ldap_err2stringA,ldap_first_entry,ldap_get_dnW,strlen,free,ldap_memfreeW,ldap_first_attributeW,strlen,ldap_get_values_lenW,strcmp,ldap_value_free_len,free,ldap_memfreeW,ldap_next_attributeW,ber_free,ldap_next_entry,ldap_get_dnW,ldap_value_free_len,free,ldap_memfreeW,ber_free,ldap_value_free_len,free,free,ldap_memfreeW,free,ldap_memfreeW, 23_2_6CF77820
Source: C:\Users\user\AppData\Local\Programs\Advanced ReclaiMe Free RAID Recovery Free\BackupExtractor.exe Code function: 23_2_6CF956A0 bind,WSAGetLastError, 23_2_6CF956A0
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs