Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0034DBBE |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0031C2A2 FindFirstFileExW, | 0_2_0031C2A2 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_003568EE FindFirstFileW,FindClose, | 0_2_003568EE |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0035698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, | 0_2_0035698F |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_0034D076 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_0034D3A9 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00359642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00359642 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0035979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0035979D |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00359B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, | 0_2_00359B2B |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00355C97 FindFirstFileW,FindNextFileW,FindClose, | 0_2_00355C97 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0042B5C3 NtClose, | 2_2_0042B5C3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972B60 NtClose,LdrInitializeThunk, | 2_2_03972B60 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972DF0 NtQuerySystemInformation,LdrInitializeThunk, | 2_2_03972DF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039735C0 NtCreateMutant,LdrInitializeThunk, | 2_2_039735C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03974340 NtSetContextThread, | 2_2_03974340 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03974650 NtSuspendThread, | 2_2_03974650 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972B80 NtQueryInformationFile, | 2_2_03972B80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972BA0 NtEnumerateValueKey, | 2_2_03972BA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972BF0 NtAllocateVirtualMemory, | 2_2_03972BF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972BE0 NtQueryValueKey, | 2_2_03972BE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972AB0 NtWaitForSingleObject, | 2_2_03972AB0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972AD0 NtReadFile, | 2_2_03972AD0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972AF0 NtWriteFile, | 2_2_03972AF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972F90 NtProtectVirtualMemory, | 2_2_03972F90 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972FB0 NtResumeThread, | 2_2_03972FB0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972FA0 NtQuerySection, | 2_2_03972FA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972FE0 NtCreateFile, | 2_2_03972FE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972F30 NtCreateSection, | 2_2_03972F30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972F60 NtCreateProcessEx, | 2_2_03972F60 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972E80 NtReadVirtualMemory, | 2_2_03972E80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972EA0 NtAdjustPrivilegesToken, | 2_2_03972EA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972EE0 NtQueueApcThread, | 2_2_03972EE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972E30 NtWriteVirtualMemory, | 2_2_03972E30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972DB0 NtEnumerateKey, | 2_2_03972DB0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972DD0 NtDelayExecution, | 2_2_03972DD0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972D10 NtMapViewOfSection, | 2_2_03972D10 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972D00 NtSetInformationFile, | 2_2_03972D00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972D30 NtUnmapViewOfSection, | 2_2_03972D30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972CA0 NtQueryInformationToken, | 2_2_03972CA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972CC0 NtQueryVirtualMemory, | 2_2_03972CC0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972CF0 NtOpenProcess, | 2_2_03972CF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972C00 NtQueryInformationProcess, | 2_2_03972C00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972C70 NtFreeVirtualMemory, | 2_2_03972C70 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03972C60 NtCreateKey, | 2_2_03972C60 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03973090 NtSetValueKey, | 2_2_03973090 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03973010 NtOpenDirectoryObject, | 2_2_03973010 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039739B0 NtGetContextThread, | 2_2_039739B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03973D10 NtOpenProcessToken, | 2_2_03973D10 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03973D70 NtOpenThread, | 2_2_03973D70 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002EBF40 | 0_2_002EBF40 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002E8060 | 0_2_002E8060 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00352046 | 0_2_00352046 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00348298 | 0_2_00348298 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0031E4FF | 0_2_0031E4FF |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0031676B | 0_2_0031676B |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00374873 | 0_2_00374873 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0030CAA0 | 0_2_0030CAA0 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002ECAF0 | 0_2_002ECAF0 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002FCC39 | 0_2_002FCC39 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00316DD9 | 0_2_00316DD9 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002FD064 | 0_2_002FD064 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002E90B7 | 0_2_002E90B7 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002FB119 | 0_2_002FB119 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002E91C0 | 0_2_002E91C0 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00301394 | 0_2_00301394 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00301706 | 0_2_00301706 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0030781B | 0_2_0030781B |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002E7920 | 0_2_002E7920 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_002F997D | 0_2_002F997D |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_003019B0 | 0_2_003019B0 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00307A4A | 0_2_00307A4A |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00301C77 | 0_2_00301C77 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00307CA7 | 0_2_00307CA7 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00333CD5 | 0_2_00333CD5 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0036BE44 | 0_2_0036BE44 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00319EEE | 0_2_00319EEE |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00301F32 | 0_2_00301F32 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_039935F0 | 0_2_039935F0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00401170 | 2_2_00401170 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_004101B1 | 2_2_004101B1 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_004101B3 | 2_2_004101B3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00403270 | 2_2_00403270 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0042DA03 | 2_2_0042DA03 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00416AC3 | 2_2_00416AC3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_004103D3 | 2_2_004103D3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0040E44B | 2_2_0040E44B |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0040E453 | 2_2_0040E453 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00402430 | 2_2_00402430 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0040E597 | 2_2_0040E597 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00402759 | 2_2_00402759 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_00402760 | 2_2_00402760 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0040E71F | 2_2_0040E71F |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03A003E6 | 2_2_03A003E6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0394E3F0 | 2_2_0394E3F0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FA352 | 2_2_039FA352 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039C02C0 | 2_2_039C02C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E0274 | 2_2_039E0274 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03A001AA | 2_2_03A001AA |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F41A2 | 2_2_039F41A2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F81CC | 2_2_039F81CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039DA118 | 2_2_039DA118 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03930100 | 2_2_03930100 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039C8158 | 2_2_039C8158 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039D2000 | 2_2_039D2000 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0393C7C0 | 2_2_0393C7C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03964750 | 2_2_03964750 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03940770 | 2_2_03940770 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0395C6E0 | 2_2_0395C6E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03A00591 | 2_2_03A00591 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03940535 | 2_2_03940535 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039EE4F6 | 2_2_039EE4F6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E4420 | 2_2_039E4420 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F2446 | 2_2_039F2446 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F6BD7 | 2_2_039F6BD7 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FAB40 | 2_2_039FAB40 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0393EA80 | 2_2_0393EA80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03A0A9A6 | 2_2_03A0A9A6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039429A0 | 2_2_039429A0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03956962 | 2_2_03956962 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039268B8 | 2_2_039268B8 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0396E8F0 | 2_2_0396E8F0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0394A840 | 2_2_0394A840 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03942840 | 2_2_03942840 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039BEFA0 | 2_2_039BEFA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03932FC8 | 2_2_03932FC8 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0394CFE0 | 2_2_0394CFE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03960F30 | 2_2_03960F30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E2F30 | 2_2_039E2F30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03982F28 | 2_2_03982F28 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039B4F40 | 2_2_039B4F40 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03952E90 | 2_2_03952E90 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FCE93 | 2_2_039FCE93 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FEEDB | 2_2_039FEEDB |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FEE26 | 2_2_039FEE26 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03940E59 | 2_2_03940E59 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03958DBF | 2_2_03958DBF |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0393ADE0 | 2_2_0393ADE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039DCD1F | 2_2_039DCD1F |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0394AD00 | 2_2_0394AD00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E0CB5 | 2_2_039E0CB5 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03930CF2 | 2_2_03930CF2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03940C00 | 2_2_03940C00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0398739A | 2_2_0398739A |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F132D | 2_2_039F132D |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0392D34C | 2_2_0392D34C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039452A0 | 2_2_039452A0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0395B2C0 | 2_2_0395B2C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E12ED | 2_2_039E12ED |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0394B1B0 | 2_2_0394B1B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03A0B16B | 2_2_03A0B16B |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0392F172 | 2_2_0392F172 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0397516C | 2_2_0397516C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039EF0CC | 2_2_039EF0CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039470C0 | 2_2_039470C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F70E9 | 2_2_039F70E9 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FF0E0 | 2_2_039FF0E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FF7B0 | 2_2_039FF7B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F16CC | 2_2_039F16CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03985630 | 2_2_03985630 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039DD5B0 | 2_2_039DD5B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F7571 | 2_2_039F7571 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FF43F | 2_2_039FF43F |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03931460 | 2_2_03931460 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0395FB80 | 2_2_0395FB80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039B5BF0 | 2_2_039B5BF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0397DBF9 | 2_2_0397DBF9 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FFB76 | 2_2_039FFB76 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039DDAAC | 2_2_039DDAAC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03985AA0 | 2_2_03985AA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039E1AA3 | 2_2_039E1AA3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039EDAC6 | 2_2_039EDAC6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FFA49 | 2_2_039FFA49 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F7A46 | 2_2_039F7A46 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039B3A6C | 2_2_039B3A6C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039D5910 | 2_2_039D5910 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03949950 | 2_2_03949950 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0395B950 | 2_2_0395B950 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039438E0 | 2_2_039438E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039AD800 | 2_2_039AD800 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03941F92 | 2_2_03941F92 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FFFB1 | 2_2_039FFFB1 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FFF09 | 2_2_039FFF09 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03949EB0 | 2_2_03949EB0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_0395FDC0 | 2_2_0395FDC0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F1D5A | 2_2_039F1D5A |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_03943D40 | 2_2_03943D40 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039F7D73 | 2_2_039F7D73 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039FFCF2 | 2_2_039FFCF2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 2_2_039B9C32 | 2_2_039B9C32 |
Source: 2.2.svchost.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23 |
Source: 2.2.svchost.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23 |
Source: 00000002.00000002.1367860374.0000000000400000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23 |
Source: 00000002.00000002.1368095229.0000000003750000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0034DBBE |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0031C2A2 FindFirstFileExW, | 0_2_0031C2A2 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_003568EE FindFirstFileW,FindClose, | 0_2_003568EE |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0035698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, | 0_2_0035698F |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_0034D076 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0034D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_0034D3A9 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00359642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00359642 |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_0035979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0035979D |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00359B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, | 0_2_00359B2B |
Source: C:\Users\user\Desktop\4iDSIZ8MhI.exe | Code function: 0_2_00355C97 FindFirstFileW,FindNextFileW,FindClose, | 0_2_00355C97 |