Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_00406301 FindFirstFileW,FindClose, | 0_2_00406301 |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, | 0_2_00406CC7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006647B7 GetFileAttributesW,FindFirstFileW,FindClose, | 15_2_006647B7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 15_2_0066F8A3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00663E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 15_2_00663E72 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 15_2_0066C16C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066CB81 FindFirstFileW,FindClose, | 15_2_0066CB81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 15_2_0066CC0C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 15_2_0066F445 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 15_2_0066F5A2 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00663B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 15_2_00663B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CC16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 21_2_006CC16C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C47B7 GetFileAttributesW,FindFirstFileW,FindClose, | 21_2_006C47B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CCB81 FindFirstFileW,FindClose, | 21_2_006CCB81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CCC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 21_2_006CCC0C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 21_2_006CF445 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 21_2_006CF5A2 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 21_2_006CF8A3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C3B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 21_2_006C3B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C3E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 21_2_006C3E72 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C16000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, | 21_2_00C16000 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C36770 CreateDirectoryA,FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, | 21_2_00C36770 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B81F9C FindClose,FindFirstFileExW,GetLastError, | 21_2_00B81F9C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE3F40 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, | 21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B82022 GetLastError,GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, | 21_2_00B82022 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: unknown | TCP traffic detected without corresponding DNS query: 3.36.173.8 |
Source: External24.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: External24.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: External24.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: External24.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://crl.globalsign.com/gs/gscodesigng2.crl0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingg2.crl0T |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://crl.globalsign.net/root.crl0 |
Source: External24.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: External24.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: External24.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: External24.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: External24.exe | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: External24.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: External24.exe | String found in binary or memory: http://ocsp.digicert.com0 |
Source: External24.exe | String found in binary or memory: http://ocsp.digicert.com0A |
Source: External24.exe | String found in binary or memory: http://ocsp.digicert.com0C |
Source: External24.exe | String found in binary or memory: http://ocsp.digicert.com0X |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesigng20 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesigng2.crt04 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingg2.crt0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 0000000A.00000000.1667514341.0000000000728000.00000002.00000001.01000000.00000005.sdmp, PixelFlow.pif, 0000000F.00000002.1740315426.00000000006C8000.00000002.00000001.01000000.00000008.sdmp, Lawyers.pif, 00000015.00000000.2875071248.0000000000728000.00000002.00000001.01000000.00000005.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Ivory.0.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: External24.exe | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: Lawyers.pif, Lawyers.pif, 00000015.00000002.3501008072.0000000000B50000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://db-ip.com/ |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33 |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33a |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://db-ip.com/demo/home.php?s=8.46.123.33tQ0 |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://db-ip.com:443/demo/home.php?s=8.46.123.33j |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: Lawyers.pif, Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EEB000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000F0E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/ |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/Mozilla/5.0 |
Source: Lawyers.pif, 00000015.00000002.3501008072.0000000000B50000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000EEB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/t |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EC0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/widget/demo/8.46.123.33 |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F1F000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501596780.0000000000F20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io:443/widget/demo/8.46.123.33 |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://support.mozilla.org |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.zvXrErQ5GYDF |
Source: Lawyers.pif, 00000015.00000003.3018791915.000000000616A000.00000004.00000020.00020000.00000000.sdmp, lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: Lawyers.pif, 00000015.00000003.3018791915.000000000616A000.00000004.00000020.00020000.00000000.sdmp, lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: lsqPckitCOdaHistory.21.dr, ZriO6tn8Siv1History.21.dr | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EA7000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, 7yC9aM3nOPMh37Qvw5GmIXM.zip.21.dr | String found in binary or memory: https://t.me/RiseProSUPPORT |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, passwords.txt.21.dr | String found in binary or memory: https://t.me/risepro_bot |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t.me/risepro_bot33203 |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Lawyers.pif, 0000000A.00000003.1678028298.00000000048B7000.00000004.00000800.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501773338.0000000002AB2000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif.10.dr, Lawyers.pif.1.dr, Camp.0.dr | String found in binary or memory: https://www.globalsign.com/repository/03 |
Source: Lawyers.pif, 00000015.00000003.3019900839.000000000618E000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018511190.000000000616D000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021958870.000000000619A000.00000004.00000020.00020000.00000000.sdmp, 0ffAoFEXM0xBWeb Data.21.dr, IXuJ06djpYzdWeb Data.21.dr, Z7Yuxtpi7pUyWeb Data.21.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: Lawyers.pif | String found in binary or memory: https://www.maxmind.com/en/locate-my-ip-address |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2 |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, History.txt.21.dr | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/ |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018990250.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020594535.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021409514.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022662035.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020835160.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017414060.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018332936.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3023598157.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020119374.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3019672520.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020391892.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017934761.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022341285.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017683304.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021852441.0000000006154000.00000004.00000020.00020000.00000000.sdmp, 3b6N2Xdh3CYwplaces.sqlite.21.dr, D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/d |
Source: D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, History.txt.21.dr | String found in binary or memory: https://www.mozilla.org/privacy/firefox/ |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/privacy/firefox/allets |
Source: Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/privacy/firefox/e |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018990250.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020594535.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021409514.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022662035.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020835160.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017414060.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3018332936.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3023598157.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020119374.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3019672520.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3020391892.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017934761.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3022341285.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3017683304.0000000006154000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3021852441.0000000006154000.00000004.00000020.00020000.00000000.sdmp, 3b6N2Xdh3CYwplaces.sqlite.21.dr, D87fZN3R3jFeplaces.sqlite.21.dr | String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/privacy/firefox/refoxm |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_0040737E | 0_2_0040737E |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_00406EFE | 0_2_00406EFE |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_004079A2 | 0_2_004079A2 |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_004049A8 | 0_2_004049A8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0060B020 | 15_2_0060B020 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006094E0 | 15_2_006094E0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00609C80 | 15_2_00609C80 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006881C8 | 15_2_006881C8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00622325 | 15_2_00622325 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00636432 | 15_2_00636432 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0063258E | 15_2_0063258E |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0060E6F0 | 15_2_0060E6F0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0062275A | 15_2_0062275A |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00680802 | 15_2_00680802 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006388EF | 15_2_006388EF |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006369A4 | 15_2_006369A4 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00610BE0 | 15_2_00610BE0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0065EB95 | 15_2_0065EB95 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00680C7F | 15_2_00680C7F |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00668CB1 | 15_2_00668CB1 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0062CC81 | 15_2_0062CC81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00636F16 | 15_2_00636F16 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006232E9 | 15_2_006232E9 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0062F339 | 15_2_0062F339 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0061D457 | 15_2_0061D457 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0061F57E | 15_2_0061F57E |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006215E4 | 15_2_006215E4 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00601663 | 15_2_00601663 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0060F6A0 | 15_2_0060F6A0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006277F3 | 15_2_006277F3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0062DAD5 | 15_2_0062DAD5 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00621AD8 | 15_2_00621AD8 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00639C15 | 15_2_00639C15 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0061DD14 | 15_2_0061DD14 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00621EF0 | 15_2_00621EF0 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0062BF06 | 15_2_0062BF06 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006E81C8 | 21_2_006E81C8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00682325 | 21_2_00682325 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00696432 | 21_2_00696432 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0069258E | 21_2_0069258E |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0066E6F0 | 21_2_0066E6F0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0068275A | 21_2_0068275A |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006E0802 | 21_2_006E0802 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006988EF | 21_2_006988EF |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006969A4 | 21_2_006969A4 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00670BE0 | 21_2_00670BE0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006BEB95 | 21_2_006BEB95 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006E0C7F | 21_2_006E0C7F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C8CB1 | 21_2_006C8CB1 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0068CC81 | 21_2_0068CC81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00696F16 | 21_2_00696F16 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0066B020 | 21_2_0066B020 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006832E9 | 21_2_006832E9 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0068F339 | 21_2_0068F339 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0067D457 | 21_2_0067D457 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006694E0 | 21_2_006694E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0067F57E | 21_2_0067F57E |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006815E4 | 21_2_006815E4 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00661663 | 21_2_00661663 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0066F6A0 | 21_2_0066F6A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006877F3 | 21_2_006877F3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00681AD8 | 21_2_00681AD8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0068DAD5 | 21_2_0068DAD5 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00699C15 | 21_2_00699C15 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00669C80 | 21_2_00669C80 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0067DD14 | 21_2_0067DD14 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00681EF0 | 21_2_00681EF0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_0068BF06 | 21_2_0068BF06 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C100A0 | 21_2_00C100A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B9002D | 21_2_00B9002D |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C5A2B0 | 21_2_00C5A2B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B5A2C0 | 21_2_00B5A2C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BFA200 | 21_2_00BFA200 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BF6250 | 21_2_00BF6250 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C0E3C0 | 21_2_00C0E3C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE63B0 | 21_2_00BE63B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C084D0 | 21_2_00C084D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C4A480 | 21_2_00C4A480 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C2E430 | 21_2_00C2E430 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C64550 | 21_2_00C64550 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE86B0 | 21_2_00BE86B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C306D0 | 21_2_00C306D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE0600 | 21_2_00BE0600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BF88B0 | 21_2_00BF88B0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C4A930 | 21_2_00C4A930 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C34BD0 | 21_2_00C34BD0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C4AD00 | 21_2_00C4AD00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BEAF60 | 21_2_00BEAF60 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BEF0D0 | 21_2_00BEF0D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C2F030 | 21_2_00C2F030 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BED3A0 | 21_2_00BED3A0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C8F550 | 21_2_00C8F550 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C03600 | 21_2_00C03600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C27600 | 21_2_00C27600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C01630 | 21_2_00C01630 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE5790 | 21_2_00BE5790 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B5B8E0 | 21_2_00B5B8E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BFDB20 | 21_2_00BFDB20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B59C90 | 21_2_00B59C90 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BD1C10 | 21_2_00BD1C10 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C47D00 | 21_2_00C47D00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C11F20 | 21_2_00C11F20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE3F40 | 21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C720D0 | 21_2_00C720D0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C460E0 | 21_2_00C460E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BD611D | 21_2_00BD611D |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C3E170 | 21_2_00C3E170 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BF4320 | 21_2_00BF4320 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B9036F | 21_2_00B9036F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C40450 | 21_2_00C40450 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C485F0 | 21_2_00C485F0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BD45E0 | 21_2_00BD45E0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA47BF | 21_2_00BA47BF |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C42820 | 21_2_00C42820 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B8A928 | 21_2_00B8A928 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C96970 | 21_2_00C96970 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B8C960 | 21_2_00B8C960 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA8BB0 | 21_2_00BA8BB0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C48B40 | 21_2_00C48B40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C3EC40 | 21_2_00C3EC40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C84D40 | 21_2_00C84D40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C96D20 | 21_2_00C96D20 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C56EA0 | 21_2_00C56EA0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C66EA0 | 21_2_00C66EA0 |
Source: unknown | Process created: C:\Users\user\Desktop\External24.exe "C:\Users\user\Desktop\External24.exe" | |
Source: C:\Users\user\Desktop\External24.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Forgot Forgot.cmd & Forgot.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 292668 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "towersallowancemeaninghelp" Wine | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Therefore + Physical + Inflation + Inspections + Sharon + Lung + Appearance + Warming + Army + Latinas + Anytime + Wiley + Zoning + Cincinnati + Accidents + Helena 292668\r | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif 292668\Lawyers.pif 292668\r | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 | |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "PixelFlow" /tr "wscript //B 'C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js'" /sc onlogon /F /RL HIGHEST | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\wscript.exe C:\Windows\system32\wscript.EXE //B "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js" | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif" "C:\Users\user\AppData\Local\PixelFlow Creations\m" | |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | |
Source: C:\Users\user\Desktop\External24.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Forgot Forgot.cmd & Forgot.cmd | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 292668 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "towersallowancemeaninghelp" Wine | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Therefore + Physical + Inflation + Inspections + Sharon + Lung + Appearance + Warming + Army + Latinas + Anytime + Wiley + Zoning + Cincinnati + Accidents + Helena 292668\r | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif 292668\Lawyers.pif 292668\r | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "PixelFlow" /tr "wscript //B 'C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.js'" /sc onlogon /F /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Process created: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif "C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif" "C:\Users\user\AppData\Local\PixelFlow Creations\m" | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: gpedit.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dssec.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dsuiext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: authz.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_00406301 FindFirstFileW,FindClose, | 0_2_00406301 |
Source: C:\Users\user\Desktop\External24.exe | Code function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, | 0_2_00406CC7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_006647B7 GetFileAttributesW,FindFirstFileW,FindClose, | 15_2_006647B7 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 15_2_0066F8A3 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00663E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 15_2_00663E72 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 15_2_0066C16C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066CB81 FindFirstFileW,FindClose, | 15_2_0066CB81 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 15_2_0066CC0C |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 15_2_0066F445 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_0066F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 15_2_0066F5A2 |
Source: C:\Users\user\AppData\Local\PixelFlow Creations\PixelFlow.pif | Code function: 15_2_00663B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 15_2_00663B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CC16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 21_2_006CC16C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C47B7 GetFileAttributesW,FindFirstFileW,FindClose, | 21_2_006C47B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CCB81 FindFirstFileW,FindClose, | 21_2_006CCB81 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CCC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 21_2_006CCC0C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 21_2_006CF445 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 21_2_006CF5A2 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006CF8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 21_2_006CF8A3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C3B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 21_2_006C3B4F |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_006C3E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 21_2_006C3E72 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C16000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, | 21_2_00C16000 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C36770 CreateDirectoryA,FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, | 21_2_00C36770 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B81F9C FindClose,FindFirstFileExW,GetLastError, | 21_2_00B81F9C |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE3F40 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, | 21_2_00BE3F40 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00B82022 GetLastError,GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, | 21_2_00B82022 |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000EF1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000& |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}G |
Source: Lawyers.pif, 00000015.00000002.3502285683.0000000006176000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501287006.0000000000F05000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}>Y0W |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006120000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&0000001.19041.2006_none_d94bc80de1097097\gdiplus.dlllYrc |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000002.3501287006.0000000000EF1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: Lawyers.pif, 00000015.00000002.3502285683.0000000006176000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}txt*N |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006120000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/7rrP9UK+nYJkDUaruLFsmiax3GAXC2Igj63N1koqBHsy38rIIvg==_b3i0u6LLcKCMUaF/UlQgEPSL9PtLZ21CuT1dJkfCzME=*wT< |
Source: Lawyers.pif, 00000015.00000002.3502181741.0000000006154000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 9e146be9-c76a-4720-bcdb-53011b87bd06_{a33c7340-61ca-11ee-8c18-806e6f6e6963}_\\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}_8D4D65C4 |
Source: Lawyers.pif, 00000015.00000003.2961599363.0000000000F08000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Lawyers.pif, 00000015.00000002.3501596780.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Lawyers.pif, 00000015.00000003.3349195349.0000000000F26000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWjS |
Source: PixelFlow.pif, 0000000F.00000002.1742294834.00000000039DE000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif, 0000000F.00000003.1735274226.00000000039D7000.00000004.00000020.00020000.00000000.sdmp, PixelFlow.pif, 0000000F.00000003.1734640266.00000000039CE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BAA102 mov eax, dword ptr fs:[00000030h] | 21_2_00BAA102 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BAA102 mov ecx, dword ptr fs:[00000030h] | 21_2_00BAA102 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C186C0 mov eax, dword ptr fs:[00000030h] | 21_2_00C186C0 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] | 21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] | 21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BAA6B7 mov eax, dword ptr fs:[00000030h] | 21_2_00BAA6B7 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] | 21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] | 21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA95B8 mov eax, dword ptr fs:[00000030h] | 21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BA95B8 mov ecx, dword ptr fs:[00000030h] | 21_2_00BA95B8 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C23600 mov eax, dword ptr fs:[00000030h] | 21_2_00C23600 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BE5790 mov eax, dword ptr fs:[00000030h] | 21_2_00BE5790 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BADB00 mov eax, dword ptr fs:[00000030h] | 21_2_00BADB00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00BADB00 mov eax, dword ptr fs:[00000030h] | 21_2_00BADB00 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C26280 mov eax, dword ptr fs:[00000030h] | 21_2_00C26280 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C1A502 mov eax, dword ptr fs:[00000030h] | 21_2_00C1A502 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C1A6B3 mov eax, dword ptr fs:[00000030h] | 21_2_00C1A6B3 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C18C58 mov eax, dword ptr fs:[00000030h] | 21_2_00C18C58 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | Code function: 21_2_00C16D80 mov eax, dword ptr fs:[00000030h] | 21_2_00C16D80 |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\places.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\formhistory.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\chrome-extension_blnieiiffboillknjnepogjhkgnoapac_0.indexeddb.leveldb\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\chrome-extension_cjelfplplebdjjenllpjcblmjkfcffne_0.indexeddb.leveldb\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\signons.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\logins.json | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\formhistory.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\signons.sqlite | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\logins.json | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\292668\Lawyers.pif | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\CURRENT | Jump to behavior |