Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_00406301 FindFirstFileW,FindClose, |
0_2_00406301 |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406CC7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006647B7 GetFileAttributesW,FindFirstFileW,FindClose, |
15_2_006647B7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0066F8A3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00663E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00663E72 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0066C16C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066CB81 FindFirstFileW,FindClose, |
15_2_0066CB81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
15_2_0066CC0C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0066F445 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0066F5A2 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00663B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00663B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CC16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_006CC16C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C47B7 GetFileAttributesW,FindFirstFileW,FindClose, |
21_2_006C47B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CCB81 FindFirstFileW,FindClose, |
21_2_006CCB81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CCC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
21_2_006CCC0C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_006CF445 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_006CF5A2 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_006CF8A3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C3B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_006C3B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C3E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_006C3E72 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C16000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_00C16000 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C36770 CreateDirectoryA,FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
21_2_00C36770 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B81F9C FindClose,FindFirstFileExW,GetLastError, |
21_2_00B81F9C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE3F40 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, |
21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B82022 GetLastError,GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
21_2_00B82022 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: External24.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: External24.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: External24.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: External24.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gscodesigng2.crl0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingg2.crl0T |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://crl.globalsign.net/root.crl0 |
Source: External24.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: External24.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: External24.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: External24.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: External24.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: External24.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: External24.exe |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: External24.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: External24.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: External24.exe |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesigng20 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesigng2.crt04 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingg2.crt0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 0000000A.00000000.1667514341.0000000000728000.00000002.00000001.01000000.00000005.sdmp, PixelFlow.pif, 0000000F.00000002.1740315426.00000000006C8000.00000002.00000001.01000000.00000008.sdmp, Lawyers.pif, 00000015.00000000.2875071248.0000000000728000.00000002.00000001.01000000.00000005.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Ivory.0.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: External24.exe |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: Lawyers.pif, Lawyers.pif, 00000015.00000002.3501008072.0000000000B50000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: http://www.winimage.com/zLibDll |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://db-ip.com/ |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33 |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33a |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33tQ0 |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://db-ip.com:443/demo/home.php?s=8.46.123.33j |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: Lawyers.pif, Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EEB000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000F0E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/ |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/Mozilla/5.0 |
Source: Lawyers.pif, 00000015.00000002.3501008072.0000000000B50000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000EEB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/t |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EC0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/widget/demo/8.46.123.33 |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io:443/widget/demo/8.46.123.33 |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://support.mozilla.org |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.zvXrErQ5GYDF |
Source: Lawyers.pif, 00000015.00000003.3018791915.000000000616A000.00000004.00000020.00020000.00000000.sdmp, lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: Lawyers.pif, 00000015.00000003.3018791915.000000000616A000.00000004.00000020.00020000.00000000.sdmp, lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EA7000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, 7yC9aM3nOPMh37Qvw5GmIXM.zip.21.dr |
String found in binary or memory: https://t.me/RiseProSUPPORT |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, passwords.txt.21.dr |
String found in binary or memory: https://t.me/risepro_bot |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://t.me/risepro_bot33203 |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/03 |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr |
String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: Lawyers.pif |
String found in binary or memory: https://www.maxmind.com/en/locate-my-ip-address |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2 |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, History.txt.21.dr |
String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/ |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018990250.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020594535.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021409514.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022662035.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020835160.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017414060.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018332936.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3023598157.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020119374.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3019672520.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020391892.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017934761.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022341285.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017683304.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021852441.0000000006154000.00000004.00000020.00020000.00000000.sdmp, 3b6N2Xdh3CYwplaces.sqlite.21.dr, D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/d |
Source: D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, History.txt.21.dr |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/ |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/allets |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/e |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018990250.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020594535.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021409514.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022662035.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020835160.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017414060.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018332936.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3023598157.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020119374.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3019672520.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020391892.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017934761.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022341285.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017683304.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021852441.0000000006154000.00000004.00000020.00020000.00000000.sdmp, 3b6N2Xdh3CYwplaces.sqlite.21.dr, D87fZN3R3jFeplaces.sqlite.21.dr |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.mozilla.org/privacy/firefox/refoxm |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_0040737E |
0_2_0040737E |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_00406EFE |
0_2_00406EFE |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_004079A2 |
0_2_004079A2 |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_004049A8 |
0_2_004049A8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0060B020 |
15_2_0060B020 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006094E0 |
15_2_006094E0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00609C80 |
15_2_00609C80 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006881C8 |
15_2_006881C8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00622325 |
15_2_00622325 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00636432 |
15_2_00636432 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0063258E |
15_2_0063258E |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0060E6F0 |
15_2_0060E6F0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0062275A |
15_2_0062275A |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00680802 |
15_2_00680802 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006388EF |
15_2_006388EF |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006369A4 |
15_2_006369A4 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00610BE0 |
15_2_00610BE0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0065EB95 |
15_2_0065EB95 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00680C7F |
15_2_00680C7F |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00668CB1 |
15_2_00668CB1 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0062CC81 |
15_2_0062CC81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00636F16 |
15_2_00636F16 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006232E9 |
15_2_006232E9 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0062F339 |
15_2_0062F339 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0061D457 |
15_2_0061D457 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0061F57E |
15_2_0061F57E |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006215E4 |
15_2_006215E4 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00601663 |
15_2_00601663 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0060F6A0 |
15_2_0060F6A0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006277F3 |
15_2_006277F3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0062DAD5 |
15_2_0062DAD5 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00621AD8 |
15_2_00621AD8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00639C15 |
15_2_00639C15 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0061DD14 |
15_2_0061DD14 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00621EF0 |
15_2_00621EF0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0062BF06 |
15_2_0062BF06 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006E81C8 |
21_2_006E81C8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00682325 |
21_2_00682325 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00696432 |
21_2_00696432 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0069258E |
21_2_0069258E |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0066E6F0 |
21_2_0066E6F0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0068275A |
21_2_0068275A |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006E0802 |
21_2_006E0802 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006988EF |
21_2_006988EF |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006969A4 |
21_2_006969A4 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00670BE0 |
21_2_00670BE0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006BEB95 |
21_2_006BEB95 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006E0C7F |
21_2_006E0C7F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C8CB1 |
21_2_006C8CB1 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0068CC81 |
21_2_0068CC81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00696F16 |
21_2_00696F16 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0066B020 |
21_2_0066B020 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006832E9 |
21_2_006832E9 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0068F339 |
21_2_0068F339 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0067D457 |
21_2_0067D457 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006694E0 |
21_2_006694E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0067F57E |
21_2_0067F57E |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006815E4 |
21_2_006815E4 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00661663 |
21_2_00661663 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0066F6A0 |
21_2_0066F6A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006877F3 |
21_2_006877F3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00681AD8 |
21_2_00681AD8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0068DAD5 |
21_2_0068DAD5 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00699C15 |
21_2_00699C15 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00669C80 |
21_2_00669C80 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0067DD14 |
21_2_0067DD14 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00681EF0 |
21_2_00681EF0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_0068BF06 |
21_2_0068BF06 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C100A0 |
21_2_00C100A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B9002D |
21_2_00B9002D |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C5A2B0 |
21_2_00C5A2B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B5A2C0 |
21_2_00B5A2C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BFA200 |
21_2_00BFA200 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BF6250 |
21_2_00BF6250 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C0E3C0 |
21_2_00C0E3C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE63B0 |
21_2_00BE63B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C084D0 |
21_2_00C084D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C4A480 |
21_2_00C4A480 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C2E430 |
21_2_00C2E430 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C64550 |
21_2_00C64550 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE86B0 |
21_2_00BE86B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C306D0 |
21_2_00C306D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE0600 |
21_2_00BE0600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BF88B0 |
21_2_00BF88B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C4A930 |
21_2_00C4A930 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C34BD0 |
21_2_00C34BD0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C4AD00 |
21_2_00C4AD00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BEAF60 |
21_2_00BEAF60 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BEF0D0 |
21_2_00BEF0D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C2F030 |
21_2_00C2F030 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BED3A0 |
21_2_00BED3A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C8F550 |
21_2_00C8F550 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C03600 |
21_2_00C03600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C27600 |
21_2_00C27600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C01630 |
21_2_00C01630 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE5790 |
21_2_00BE5790 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B5B8E0 |
21_2_00B5B8E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BFDB20 |
21_2_00BFDB20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B59C90 |
21_2_00B59C90 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BD1C10 |
21_2_00BD1C10 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C47D00 |
21_2_00C47D00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C11F20 |
21_2_00C11F20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE3F40 |
21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C720D0 |
21_2_00C720D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C460E0 |
21_2_00C460E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BD611D |
21_2_00BD611D |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C3E170 |
21_2_00C3E170 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BF4320 |
21_2_00BF4320 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B9036F |
21_2_00B9036F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C40450 |
21_2_00C40450 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C485F0 |
21_2_00C485F0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BD45E0 |
21_2_00BD45E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA47BF |
21_2_00BA47BF |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C42820 |
21_2_00C42820 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B8A928 |
21_2_00B8A928 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C96970 |
21_2_00C96970 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B8C960 |
21_2_00B8C960 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA8BB0 |
21_2_00BA8BB0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C48B40 |
21_2_00C48B40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C3EC40 |
21_2_00C3EC40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C84D40 |
21_2_00C84D40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C96D20 |
21_2_00C96D20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C56EA0 |
21_2_00C56EA0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C66EA0 |
21_2_00C66EA0 |
Source: unknown |
Process created: C:\Users\user\Desktop\External24.exe "C:\Users\user\Desktop\External24.exe" |
|
Source: C:\Users\user\Desktop\External24.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Forgot Forgot.cmd & Forgot.cmd |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 292668 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "towersallowancemeaninghelp" Wine |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Therefore + Physical + Inflation + Inspections + Sharon + Lung + Appearance + Warming + Army + Latinas + Anytime + Wiley + Zoning + Cincinnati + Accidents + Helena 292668\r |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif 292668\Lawyers.pif 292668\r |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
|
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "PixelFlow" /tr "wscript //B 'C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js'" /sc onlogon /F /RL HIGHEST |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Windows\System32\wscript.exe C:\Windows\system32\wscript.EXE //B "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js" |
|
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif" "C:\Users\user\AppData\Local\PixelFlow Creations\m" |
|
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
|
Source: C:\Users\user\Desktop\External24.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Forgot Forgot.cmd & Forgot.cmd |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 292668 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "towersallowancemeaninghelp" Wine |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Therefore + Physical + Inflation + Inspections + Sharon + Lung + Appearance + Warming + Army + Latinas + Anytime + Wiley + Zoning + Cincinnati + Accidents + Helena 292668\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif 292668\Lawyers.pif 292668\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "PixelFlow" /tr "wscript //B 'C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js'" /sc onlogon /F /RL HIGHEST |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif" "C:\Users\user\AppData\Local\PixelFlow Creations\m" |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: jscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: gpedit.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dssec.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dsuiext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dsrole.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: logoncli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ntdsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: authz.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: devobj.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: webio.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_00406301 FindFirstFileW,FindClose, |
0_2_00406301 |
Source: C:\Users\user\Desktop\External24.exe |
Code function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406CC7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_006647B7 GetFileAttributesW,FindFirstFileW,FindClose, |
15_2_006647B7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0066F8A3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00663E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00663E72 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0066C16C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066CB81 FindFirstFileW,FindClose, |
15_2_0066CB81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
15_2_0066CC0C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0066F445 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_0066F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0066F5A2 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif |
Code function: 15_2_00663B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00663B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CC16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_006CC16C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C47B7 GetFileAttributesW,FindFirstFileW,FindClose, |
21_2_006C47B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CCB81 FindFirstFileW,FindClose, |
21_2_006CCB81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CCC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
21_2_006CCC0C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_006CF445 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_006CF5A2 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006CF8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_006CF8A3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C3B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_006C3B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_006C3E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_006C3E72 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C16000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_00C16000 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C36770 CreateDirectoryA,FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
21_2_00C36770 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B81F9C FindClose,FindFirstFileExW,GetLastError, |
21_2_00B81F9C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE3F40 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, |
21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00B82022 GetLastError,GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
21_2_00B82022 |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000EF1000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000& |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}G |
Source: Lawyers.pif, 00000015.00000002.3502285683.0000000006176000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000F05000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}>Y0W |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006120000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&0000001.19041.2006_none_d94bc80de1097097\gdiplus.dlllYrc |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EF1000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: Lawyers.pif, 00000015.00000002.3502285683.0000000006176000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}txt*N |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006120000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/7rrP9UK+nYJkDUaruLFsmiax3GAXC2Igj63N1koqBHsy38rIIvg==_b3i0u6LLcKCMUaF/UlQgEPSL9PtLZ21CuT1dJkfCzME=*wT< |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: 9e146be9-c76a-4720-bcdb-53011b87bd06_{a33c7340-61ca-11ee-8c18-806e6f6e6963}_\\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}_8D4D65C4 |
Source: Lawyers.pif, 00000015.00000003.2961599363.0000000000F08000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAWjS |
Source: PixelFlow.pif, 0000000F.00000002.1742294834.00000000039DE000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif, 0000000F.00000003.1735274226.00000000039D7000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif, 0000000F.00000003.1734640266.00000000039CE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BAA102 mov eax, dword ptr fs:[00000030h] |
21_2_00BAA102 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BAA102 mov ecx, dword ptr fs:[00000030h] |
21_2_00BAA102 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C186C0 mov eax, dword ptr fs:[00000030h] |
21_2_00C186C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] |
21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] |
21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] |
21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] |
21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] |
21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] |
21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BA95B8 mov ecx, dword ptr fs:[00000030h] |
21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] |
21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BE5790 mov eax, dword ptr fs:[00000030h] |
21_2_00BE5790 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BADB00 mov eax, dword ptr fs:[00000030h] |
21_2_00BADB00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00BADB00 mov eax, dword ptr fs:[00000030h] |
21_2_00BADB00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C26280 mov eax, dword ptr fs:[00000030h] |
21_2_00C26280 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C1A502 mov eax, dword ptr fs:[00000030h] |
21_2_00C1A502 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C1A6B3 mov eax, dword ptr fs:[00000030h] |
21_2_00C1A6B3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C18C58 mov eax, dword ptr fs:[00000030h] |
21_2_00C18C58 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
Code function: 21_2_00C16D80 mov eax, dword ptr fs:[00000030h] |
21_2_00C16D80 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\places.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\formhistory.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\chrome-extension_blnieiiffboillknjnepogjhkgnoapac_0.indexeddb.leveldb\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\chrome-extension_cjelfplplebdjjenllpjcblmjkfcffne_0.indexeddb.leveldb\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\signons.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\logins.json |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\formhistory.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\signons.sqlite |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\logins.json |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\CURRENT |
Jump to behavior |