Click to jump to signature section
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00474005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00474005 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0047C2FF |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047494A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_0047494A |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047CD14 FindFirstFileW,FindClose, | 2_2_0047CD14 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_0047CD9F |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0047F5D8 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0047F735 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0047FA36 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00473CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00473CE2 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC0205 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 2_2_00EC0205 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC030D FindFirstFileA,GetLastError, | 2_2_00EC030D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EBDB35 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 2_2_00EBDB35 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Amcache.hve.5.dr | String found in binary or memory: http://upx.sf.net |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000000.1797199517.00000000004D9000.00000002.00000001.01000000.00000006.sdmp, Autoit3.exe.1.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: JiH0aUfOU6.exe | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Autoit3.exe.1.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FD3000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.1.dr | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: JiH0aUfOU6.exe, 00000000.00000003.1790322712.0000000003330000.00000004.00001000.00020000.00000000.sdmp, JiH0aUfOU6.exe, 00000000.00000003.1790816806.000000007F2FB000.00000004.00001000.00020000.00000000.sdmp, JiH0aUfOU6.tmp, 00000001.00000000.1792796648.0000000000751000.00000020.00000001.01000000.00000004.sdmp, JiH0aUfOU6.tmp.0.dr | String found in binary or memory: https://www.innosetup.com/ |
Source: JiH0aUfOU6.exe, 00000000.00000003.1790322712.0000000003330000.00000004.00001000.00020000.00000000.sdmp, JiH0aUfOU6.exe, 00000000.00000003.1790816806.000000007F2FB000.00000004.00001000.00020000.00000000.sdmp, JiH0aUfOU6.tmp, 00000001.00000000.1792796648.0000000000751000.00000020.00000001.01000000.00000004.sdmp, JiH0aUfOU6.tmp.0.dr | String found in binary or memory: https://www.remobjects.com/ps |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00484632 OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard, | 2_2_00484632 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00484830 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,_wcscpy,GlobalUnlock,OpenClipboard,EmptyClipboard,SetClipboardData,CloseClipboard, | 2_2_00484830 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00484632 OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard, | 2_2_00484632 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00470508 GetKeyboardState,GetAsyncKeyState,GetKeyState,GetKeyState,GetAsyncKeyState,GetKeyState,GetAsyncKeyState,GetKeyState,GetAsyncKeyState,GetKeyState,GetAsyncKeyState,GetKeyState, | 2_2_00470508 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0049D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 2_2_0049D164 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED5389 GetCurrentProcessId,CreateProcessA,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,WriteProcessMemory,ResumeThread,Sleep,GetTickCount, | 2_2_00ED5389 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00468F2E _memset,DuplicateTokenEx,CloseHandle,OpenWindowStationW,GetProcessWindowStation,SetProcessWindowStation,OpenDesktopW,_wcscpy,LoadUserProfileW,CreateEnvironmentBlock,CreateProcessAsUserW,UnloadUserProfile,CloseWindowStation,CloseDesktop,SetProcessWindowStation,CloseHandle,DestroyEnvironmentBlock, | 2_2_00468F2E |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0041B020 | 2_2_0041B020 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00411663 | 2_2_00411663 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00419C80 | 2_2_00419C80 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004323F5 | 2_2_004323F5 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00498400 | 2_2_00498400 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00446502 | 2_2_00446502 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0044265E | 2_2_0044265E |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0041E6F0 | 2_2_0041E6F0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043282A | 2_2_0043282A |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004489BF | 2_2_004489BF |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00446A74 | 2_2_00446A74 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00490A3A | 2_2_00490A3A |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00420BE0 | 2_2_00420BE0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043CD51 | 2_2_0043CD51 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0046EDB2 | 2_2_0046EDB2 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00478E44 | 2_2_00478E44 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00490EB7 | 2_2_00490EB7 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00446FE6 | 2_2_00446FE6 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004333B7 | 2_2_004333B7 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0042D45D | 2_2_0042D45D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043F409 | 2_2_0043F409 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004194E0 | 2_2_004194E0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0042F628 | 2_2_0042F628 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0041F6A0 | 2_2_0041F6A0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004316B4 | 2_2_004316B4 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004378C3 | 2_2_004378C3 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043DBA5 | 2_2_0043DBA5 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00431BA8 | 2_2_00431BA8 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00449CE5 | 2_2_00449CE5 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0042DD28 | 2_2_0042DD28 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00431FC0 | 2_2_00431FC0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043BFD6 | 2_2_0043BFD6 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CE1 | 2_2_00ED4CE1 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CDA | 2_2_00ED4CDA |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: String function: 00421A36 appears 34 times | |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: String function: 00438B30 appears 42 times | |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: String function: 00430D17 appears 70 times | |
Source: JiH0aUfOU6.exe, 00000000.00000003.1790322712.000000000344E000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs JiH0aUfOU6.exe |
Source: JiH0aUfOU6.exe, 00000000.00000000.1788139711.0000000000399000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFileName vs JiH0aUfOU6.exe |
Source: JiH0aUfOU6.exe, 00000000.00000003.1790816806.000000007F5FA000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs JiH0aUfOU6.exe |
Source: JiH0aUfOU6.exe | Binary or memory string: OriginalFileName vs JiH0aUfOU6.exe |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047443D __swprintf,__swprintf,FindResourceW,LoadResource,LockResource,FindResourceW,LoadResource,SizeofResource,LockResource,CreateIconFromResourceEx, | 2_2_0047443D |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\JiH0aUfOU6.exe "C:\Users\user\Desktop\JiH0aUfOU6.exe" | |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Process created: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp "C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp" /SL5="$7047C,2802098,845824,C:\Users\user\Desktop\JiH0aUfOU6.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process created: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe "C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe" C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\script.a3x | |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7632 -s 820 | |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Process created: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp "C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp" /SL5="$7047C,2802098,845824,C:\Users\user\Desktop\JiH0aUfOU6.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process created: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe "C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe" C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\script.a3x | Jump to behavior |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043E93F push edi; ret | 2_2_0043E941 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00478A4A push FFFFFF8Bh; iretd | 2_2_00478A4C |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043EA58 push esi; ret | 2_2_0043EA5A |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00438B75 push ecx; ret | 2_2_00438B88 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0042CBF1 push eax; retf | 2_2_0042CBF8 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043EC33 push esi; ret | 2_2_0043EC35 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0043ED1C push edi; ret | 2_2_0043ED1E |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EBE6A5 push 00EBE6F6h; ret | 2_2_00EBE6EE |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED40E9 push 00ED4135h; ret | 2_2_00ED412D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED00F5 push 00ED0121h; ret | 2_2_00ED0119 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC5099 push 00EC5215h; ret | 2_2_00EC520D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED3029 push 00ED3055h; ret | 2_2_00ED304D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECD1D9 push ecx; mov dword ptr [esp], ecx | 2_2_00ECD1DE |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED52F5 push 00ED5321h; ret | 2_2_00ED5319 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED52F3 push 00ED5321h; ret | 2_2_00ED5319 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED52B5 push 00ED52E1h; ret | 2_2_00ED52D9 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC5299 push 00EC52C5h; ret | 2_2_00EC52BD |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC5291 push 00EC52C5h; ret | 2_2_00EC52BD |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED527D push 00ED52A9h; ret | 2_2_00ED52A1 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC5219 push 00EC5288h; ret | 2_2_00EC5280 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC5217 push 00EC5288h; ret | 2_2_00EC5280 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECB3D9 push 00ECB481h; ret | 2_2_00ECB479 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECB361 push 00ECB3D7h; ret | 2_2_00ECB3CF |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECB4ED push 00ECB519h; ret | 2_2_00ECB511 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECB48F push 00ECB519h; ret | 2_2_00ECB511 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4495 push 00ED44D8h; ret | 2_2_00ED44D0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4494 push 00ED44D8h; ret | 2_2_00ED44D0 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4445 push 00ED4471h; ret | 2_2_00ED4469 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED443D push 00ED4471h; ret | 2_2_00ED4469 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC05C9 push ecx; mov dword ptr [esp], eax | 2_2_00EC05CA |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECB5C2 push 00ECB635h; ret | 2_2_00ECB62D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004959B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 2_2_004959B3 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00425EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 2_2_00425EDA |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004333B7 EncodePointer,__initp_misc_winsig,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, | 2_2_004333B7 |
Source: C:\Users\user\Desktop\JiH0aUfOU6.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C6LCF.tmp\JiH0aUfOU6.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00474005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00474005 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0047C2FF |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047494A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_0047494A |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047CD14 FindFirstFileW,FindClose, | 2_2_0047CD14 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_0047CD9F |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0047F5D8 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0047F735 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0047FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0047FA36 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00473CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00473CE2 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC0205 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 2_2_00EC0205 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EC030D FindFirstFileA,GetLastError, | 2_2_00EC030D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EBDB35 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 2_2_00EBDB35 |
Source: Amcache.hve.5.dr | Binary or memory string: VMware |
Source: Amcache.hve.5.dr | Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.5.dr | Binary or memory string: vmci.syshbin |
Source: Amcache.hve.5.dr | Binary or memory string: VMware, Inc. |
Source: Autoit3.exe, Autoit3.exe, 00000002.00000003.1848964509.0000000000F43000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250471709.0000000000F06000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000003.1848964509.0000000000EF2000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250424435.0000000000EB6000.00000040.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250471709.0000000000EE2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft hyper-v video |
Source: Amcache.hve.5.dr | Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.5.dr | Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.5.dr | Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.5.dr | Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.5.dr | Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.5.dr | Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.5.dr | Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.5.dr | Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Autoit3.exe | Binary or memory string: ksJlMugAfJJiCpQzTvHPkiOXPpWhGFSwxpdVRxiinwPGhUIcRINemJjwnThIXtDiaSZYcFozQAClCBmoqTgYgjbYvufIlbsZGmuAQCTOeDegsMqvyazDdYRHIcBaADUJoIqcFMiwYOguJvZrEcIojiaKbAJwvkkMhtTxNwibjQaWdIJEkbCZFGLBqZvDWvHnFGlcEGMmcVFDAQiqcWeVrZaGXiiWDYSXmMHzucFVIOubyDBtdQsJwILHgoVXnVTmQXxT |
Source: Amcache.hve.5.dr | Binary or memory string: vmci.sys |
Source: Amcache.hve.5.dr | Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0 |
Source: Amcache.hve.5.dr | Binary or memory string: vmci.syshbin` |
Source: Autoit3.exe, 00000002.00000002.4250471709.0000000000EE2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: Amcache.hve.5.dr | Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.5.dr | Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.5.dr | Binary or memory string: VMware20,1 |
Source: Amcache.hve.5.dr | Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.5.dr | Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.5.dr | Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.5.dr | Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.5.dr | Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.5.dr | Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.5.dr | Binary or memory string: VMware PCI VMCI Bus Device |
Source: Autoit3.exe, 00000002.00000002.4250471709.0000000000F06000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000003.1848964509.0000000000F3C000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000003.1848964509.0000000000EEC000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250424435.0000000000EB6000.00000040.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250471709.0000000000EE2000.00000004.00000020.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000002.4250573331.0000000000F3D000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xRckeQNZuMKVTzSBBtqmbcsgnaBYEbZaOwjiqXNRDquAjeMRvwNRxJetYOwhpnTOcozOeCkwmEhYbtoroygOEkCQSiklrIXCdvDMwNjgtuAcCYYEizUkEfFASNbfKXpvDqnhcWPpsCRqcmTHZXPFjdfJqdVCyExbjYHtoFjxYOllWjDmCOPNQbWFVCDfVKzEvMfheByguPDYQDgGDtiQAeZFQIBlwgZUHAoAfJPXimzHuQgGFBumXBjfyNceCvcsiCcSFksJlMugAfJJiCpQzTvHPkiOXPpWhGFSwxpdVRxiinwPGhUIcRINemJjwnThIXtDiaSZYcFozQAClCBmoqTgYgjbYvufIlbsZGmuAQCTOeDegsMqvyazDdYRHIcBaADUJoIqcFMiwYOguJvZrEcIojiaKbAJwvkkMhtTxNwibjQaWdIJEkbCZFGLBqZvDWvHnFGlcEGMmcVFDAQiqcWeVrZaGXiiWDYSXmMHzucFVIOubyDBtdQsJwILHgoVXnVTmQXxTvnnbOGvWSPjitMzqQODvKenUsAagrFfHPCdLTlpNbKTQqMIlvobSoRuYKrVnZbcILYjlhRmUPKIdwWkjeSydfoaoFkFYiBUhmsHXxmbGwzXnytwvGZcmjMxNPksjyzoOwpnxtMagHdzvtlQxSTONkaGpyKRzJoXBniKvlggwFHqlpDSqxAxgCuZIooagQnJSKcxGZNVBWMQWFEirfHNZpNFyqSiWdTuCHSRerywlMfKARvvnxQifnwfniDWxSAbOWmZUJFtnAPaAMmsndpZwWoKyPRoPPFGjvGVohcZnofgjqnQRyisbAJkwJrzOKFrKQjtHzjeMwELsKILVjkldVDWqNbhQEZqKSUbAmWffVdRCpJbQHbvWMqSntglYImUYkwqBFKZGbHQUGCRnlXBfoTzlrdXYtRtHAqBBAwqBEKsiABn |
Source: Amcache.hve.5.dr | Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.5.dr | Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.5.dr | Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.5.dr | Binary or memory string: vmci.inf_amd64_68ed49469341f563 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | API call chain: ExitProcess graph end node | graph_2-111947 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | API call chain: ExitProcess graph end node | graph_2-113742 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | API call chain: ExitProcess graph end node | graph_2-113729 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | API call chain: ExitProcess graph end node | graph_2-111549 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00445CAC EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 2_2_00445CAC |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00EE0C4E mov eax, dword ptr fs:[00000030h] | 2_2_00EE0C4E |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CE1 mov eax, dword ptr fs:[00000030h] | 2_2_00ED4CE1 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CE1 mov eax, dword ptr fs:[00000030h] | 2_2_00ED4CE1 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CDA mov eax, dword ptr fs:[00000030h] | 2_2_00ED4CDA |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ED4CDA mov eax, dword ptr fs:[00000030h] | 2_2_00ED4CDA |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00ECEDF5 mov eax, dword ptr fs:[00000030h] | 2_2_00ECEDF5 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004688CD GetSecurityDescriptorDacl,_memset,GetAclInformation,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity, | 2_2_004688CD |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_004688CD GetSecurityDescriptorDacl,_memset,GetAclInformation,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity, | 2_2_004688CD |
Source: JiH0aUfOU6.tmp, 00000001.00000003.1798481983.0000000003FC5000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe, 00000002.00000000.1796828533.00000000004C6000.00000002.00000001.01000000.00000006.sdmp, Autoit3.exe.1.dr | Binary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning |
Source: Autoit3.exe | Binary or memory string: Shell_TrayWnd |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 2_2_00EBDD0D |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: GetLocaleInfoA,GetACP, | 2_2_00EC4229 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: GetLocaleInfoA, | 2_2_00EBE631 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: GetLocaleInfoA, | 2_2_00EC2CDD |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: GetLocaleInfoA, | 2_2_00EC2C91 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 2_2_00EBDE17 |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0044416A __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,__invoke_watson,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte, | 2_2_0044416A |
Source: Autoit3.exe | Binary or memory string: WIN_81 |
Source: Autoit3.exe | Binary or memory string: WIN_XP |
Source: Autoit3.exe | Binary or memory string: WIN_XPe |
Source: Autoit3.exe | Binary or memory string: WIN_VISTA |
Source: Autoit3.exe | Binary or memory string: WIN_7 |
Source: Autoit3.exe | Binary or memory string: WIN_8 |
Source: Autoit3.exe.1.dr | Binary or memory string: %.3d%S%M%H%m%Y%jX86IA64X64WIN32_NTWIN_10WIN_2016WIN_81WIN_2012R2WIN_2012WIN_8WIN_2008R2WIN_7WIN_2008WIN_VISTAWIN_2003WIN_XPeWIN_XPInstallLanguageSYSTEM\CurrentControlSet\Control\Nls\LanguageSchemeLangIDControl Panel\Appearance3, 3, 14, 5USERPROFILEUSERDOMAINUSERDNSDOMAINGetSystemWow64DirectoryWSeDebugPrivilege:winapistdcallubyte |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_0048696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 2_2_0048696E |
Source: C:\Users\user\AppData\Local\Temp\is-7ECNQ.tmp\Autoit3.exe | Code function: 2_2_00486E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 2_2_00486E32 |