Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409054 ??2@YAPAXI@Z,FindFirstFileW,FindClose, | 0_2_00409054 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00403186 FindFirstFileW,FindClose,SetLastError,CompareFileTime, | 0_2_00403186 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402A8E FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402A8E |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402B9F FindFirstFileW,FindClose,SetFileAttributesW,DeleteFileW, | 0_2_00402B9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C494A GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_007C494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_007C4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_007CC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CCD14 FindFirstFileW,FindClose, | 5_2_007CCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_007CCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_007CF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_007CF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_007CFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_007C3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB494A GetFileAttributesW,FindFirstFileW,FindClose, | 7_2_00AB494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_00AB4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_00ABC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 7_2_00ABCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABCD14 FindFirstFileW,FindClose, | 7_2_00ABCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_00ABF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_00ABF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_00ABFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_00AB3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_0043494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00434005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00434005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_0043C2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043CD14 FindFirstFileW,FindClose, | 11_2_0043CD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_0043CD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_0043F5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_0043F735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_0043FA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00433CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00433CE2 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000000.1685542446.0000000000829000.00000002.00000001.01000000.00000005.sdmp, Bonta.exe.com, 00000007.00000002.1753768535.0000000000B19000.00000002.00000001.01000000.00000006.sdmp, Inebriarti.exe.com, 00000008.00000002.2923052469.0000000000829000.00000002.00000001.01000000.00000005.sdmp, Bonta.exe.com, 0000000A.00000000.1689206168.0000000000B19000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007ED164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 5_2_007ED164 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ADD164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 7_2_00ADD164 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0045D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 11_2_0045D164 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00405420 | 0_2_00405420 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040A840 | 0_2_0040A840 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00413821 | 0_2_00413821 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_004189E1 | 0_2_004189E1 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040A1A0 | 0_2_0040A1A0 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418200 | 0_2_00418200 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040EA30 | 0_2_0040EA30 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418ABB | 0_2_00418ABB |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409B50 | 0_2_00409B50 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040BB80 | 0_2_0040BB80 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418D53 | 0_2_00418D53 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409D00 | 0_2_00409D00 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040AF00 | 0_2_0040AF00 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040AF04 | 0_2_0040AF04 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0076B020 | 5_2_0076B020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007694E0 | 5_2_007694E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00769C80 | 5_2_00769C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007823F5 | 5_2_007823F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007E8400 | 5_2_007E8400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00796502 | 5_2_00796502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0079265E | 5_2_0079265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0076E6F0 | 5_2_0076E6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078282A | 5_2_0078282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007989BF | 5_2_007989BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00796A74 | 5_2_00796A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007E0A3A | 5_2_007E0A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00770BE0 | 5_2_00770BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078CD51 | 5_2_0078CD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007BEDB2 | 5_2_007BEDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C8E44 | 5_2_007C8E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007E0EB7 | 5_2_007E0EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00796FE6 | 5_2_00796FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007833B7 | 5_2_007833B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0077D45D | 5_2_0077D45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078F409 | 5_2_0078F409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00761663 | 5_2_00761663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0077F628 | 5_2_0077F628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007816B4 | 5_2_007816B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0076F6A0 | 5_2_0076F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007878C3 | 5_2_007878C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00781BA8 | 5_2_00781BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078DBA5 | 5_2_0078DBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00799CE5 | 5_2_00799CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0077DD28 | 5_2_0077DD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078BFD6 | 5_2_0078BFD6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00781FC0 | 5_2_00781FC0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A5B020 | 7_2_00A5B020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A594E0 | 7_2_00A594E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A59C80 | 7_2_00A59C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A723F5 | 7_2_00A723F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AD8400 | 7_2_00AD8400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A86502 | 7_2_00A86502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A5E6F0 | 7_2_00A5E6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A8265E | 7_2_00A8265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7282A | 7_2_00A7282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A889BF | 7_2_00A889BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AD0A3A | 7_2_00AD0A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A86A74 | 7_2_00A86A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A60BE0 | 7_2_00A60BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AAEDB2 | 7_2_00AAEDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7CD51 | 7_2_00A7CD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AD0EB7 | 7_2_00AD0EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB8E44 | 7_2_00AB8E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A86FE6 | 7_2_00A86FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A733B7 | 7_2_00A733B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7F409 | 7_2_00A7F409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A6D45D | 7_2_00A6D45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A5F6A0 | 7_2_00A5F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A716B4 | 7_2_00A716B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A6F628 | 7_2_00A6F628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A51663 | 7_2_00A51663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A778C3 | 7_2_00A778C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7DBA5 | 7_2_00A7DBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A71BA8 | 7_2_00A71BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A89CE5 | 7_2_00A89CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A6DD28 | 7_2_00A6DD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A71FC0 | 7_2_00A71FC0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7BFD6 | 7_2_00A7BFD6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003DB020 | 11_2_003DB020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003D94E0 | 11_2_003D94E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003D9C80 | 11_2_003D9C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F23F5 | 11_2_003F23F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00458400 | 11_2_00458400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00406502 | 11_2_00406502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0040265E | 11_2_0040265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003DE6F0 | 11_2_003DE6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F282A | 11_2_003F282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_004089BF | 11_2_004089BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00406A74 | 11_2_00406A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00450A3A | 11_2_00450A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003E0BE0 | 11_2_003E0BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FCD51 | 11_2_003FCD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0042EDB2 | 11_2_0042EDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00438E44 | 11_2_00438E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00450EB7 | 11_2_00450EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00406FE6 | 11_2_00406FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F33B7 | 11_2_003F33B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FF409 | 11_2_003FF409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003ED45D | 11_2_003ED45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003EF628 | 11_2_003EF628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003D1663 | 11_2_003D1663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F16B4 | 11_2_003F16B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003DF6A0 | 11_2_003DF6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F78C3 | 11_2_003F78C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F1BA8 | 11_2_003F1BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FDBA5 | 11_2_003FDBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00409CE5 | 11_2_00409CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003EDD28 | 11_2_003EDD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FBFD6 | 11_2_003FBFD6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F1FC0 | 11_2_003F1FC0 |
Source: unknown | Process created: C:\Users\user\Desktop\Tt843YGUx5.exe "C:\Users\user\Desktop\Tt843YGUx5.exe" | |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd < Seminato.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com Inebriarti.exe.com A | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com Bonta.exe.com m | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com A | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com m | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com Pensiero.exe.com E | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 30 | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com E | |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd < Seminato.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com Inebriarti.exe.com A | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com Bonta.exe.com m | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com Pensiero.exe.com E | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 30 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com A | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com m | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com E | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587F5C pushfd ; ret | 0_3_02587FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587F5C pushfd ; ret | 0_3_02587FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587D9F push ds; retf | 0_3_02587DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587D9F push ds; retf | 0_3_02587DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587F5C pushfd ; ret | 0_3_02587FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587F5C pushfd ; ret | 0_3_02587FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587D9F push ds; retf | 0_3_02587DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_02587D9F push ds; retf | 0_3_02587DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418690 push eax; ret | 0_2_004186BE |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078E93F push edi; ret | 5_2_0078E941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078EA58 push esi; ret | 5_2_0078EA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C8A4A push FFFFFF8Bh; iretd | 5_2_007C8A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00788B75 push ecx; ret | 5_2_00788B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0077CBDB push eax; retf | 5_2_0077CBF8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078EC33 push esi; ret | 5_2_0078EC35 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0077CC06 push eax; retf | 5_2_0077CBF8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_0078ED1C push edi; ret | 5_2_0078ED1E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7E93F push edi; ret | 7_2_00A7E941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB8A4A push FFFFFF8Bh; iretd | 7_2_00AB8A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7EA58 push esi; ret | 7_2_00A7EA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A78B75 push ecx; ret | 7_2_00A78B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7EC33 push esi; ret | 7_2_00A7EC35 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A7ED1C push edi; ret | 7_2_00A7ED1E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FE93F push edi; ret | 11_2_003FE941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00438A4A push FFFFFF8Bh; iretd | 11_2_00438A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FEA58 push esi; ret | 11_2_003FEA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003F8B75 push ecx; ret | 11_2_003F8B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003ECBF4 push eax; retf | 11_2_003ECBF8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FEC33 push esi; ret | 11_2_003FEC35 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003FED1C push edi; ret | 11_2_003FED1E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007E59B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 5_2_007E59B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00775EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 5_2_00775EDA |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AD59B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 7_2_00AD59B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00A65EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 7_2_00A65EDA |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_004559B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 11_2_004559B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_003E5EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 11_2_003E5EDA |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409054 ??2@YAPAXI@Z,FindFirstFileW,FindClose, | 0_2_00409054 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00403186 FindFirstFileW,FindClose,SetLastError,CompareFileTime, | 0_2_00403186 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402A8E FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402A8E |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402B9F FindFirstFileW,FindClose,SetFileAttributesW,DeleteFileW, | 0_2_00402B9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C494A GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_007C494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_007C4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_007CC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CCD14 FindFirstFileW,FindClose, | 5_2_007CCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_007CCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_007CF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_007CF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007CFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_007CFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007C3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_007C3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB494A GetFileAttributesW,FindFirstFileW,FindClose, | 7_2_00AB494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_00AB4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_00ABC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 7_2_00ABCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABCD14 FindFirstFileW,FindClose, | 7_2_00ABCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_00ABF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_00ABF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00ABFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_00ABFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AB3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_00AB3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_0043494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00434005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00434005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_0043C2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043CD14 FindFirstFileW,FindClose, | 11_2_0043CD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_0043CD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_0043F5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_0043F735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0043FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_0043FA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00433CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00433CE2 |
Source: Bonta.exe.com, 00000007.00000003.1723632225.000000000357B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJG_112 |
Source: Bonta.exe.com, 00000007.00000003.1724859366.00000000034AF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ImcUYqPiljrtfCXuiybhGfsGnPyqZsDGmIGOiUjxeHzzdrbOpfUfToF; |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $puvSDtqYrsfhEL = 'RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUc' |
Source: Inebriarti.exe.com, 00000005.00000003.1752328553.00000000036EB000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1752435949.0000000003713000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1753609737.000000000372B000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1752745370.000000000372A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF02#121#45#44#<l& |
Source: Bonta.exe.com, 0000000A.00000002.2926103840.0000000003A06000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: GKHRXXDEQEMuQreonZWtXO |
Source: Inebriarti.exe.com, 00000005.00000003.1748045980.00000000039F3000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.2926448957.00000000041AD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUc |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711066834.0000000000CD7000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1696988883.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1696668926.0000000000C84000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1695659728.0000000000C5F000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711553711.0000000000D64000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1708881008.0000000000CD6000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711228480.0000000000D2B000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711402478.0000000000D3F000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1705319177.0000000000CBA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $VdwHnUJpYBHGiro = Execute(GKHRXxdEq("92_125_123_114_119_112_82_124_79_117_120_106_125_49_48_77_88_78_126_116_116_131_76_92_48_50",9)), $XDDiCUzGlnMH = 'ImcUYqPiljrtfCXuiybhGfsGnP' |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692968610.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693180464.0000000000E43000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $mUnGEjvcQyyHiw = Execute(rETgxIUQ("88#121#119#110#115#108#78#120#75#113#116#102#121#45#44#111#109#115#90#105#88#108#103#112#89#114#70#106#103#44#46",5)), $oMLzKVgHrLiAtG = 'kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF' |
Source: Inebriarti.exe.com, 00000005.00000003.1748045980.00000000039F3000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.2926448957.00000000041AD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp, Tt843YGUx5.exe, 00000000.00000003.1680799306.0000000003850000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: $VjItThBcFgJSTh = Execute(ekrSXFezU("71#117#108#121#104#74#104#119#86#104#117#108#100#111#43#42#92#122#80#120#74#102#88#111#93#42#44",3)), $LHtIufRxUd = 'rAAViyZFlUnFeoHWSZCenyXOWRCUyyhgfSUBjlm' |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711066834.0000000000CD7000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1696988883.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1696668926.0000000000C84000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1695659728.0000000000C5F000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711553711.0000000000D64000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1708881008.0000000000CD6000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711228480.0000000000D2B000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1711402478.0000000000D3F000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1714793493.0000000000D84000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $DxgKjzXtlDLONYMZ = 'VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJG' |
Source: Inebriarti.exe.com, 00000008.00000002.2925428546.0000000003EA4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF118#109#119#1 |
Source: Inebriarti.exe.com, 00000008.00000002.2923702335.00000000013B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $mUnGEjvcQyyHiw = Execute(rETgxIUQ("88#121#119#110#115#108#78#120#75#113#116#102#121#45#44#111#109#115#90#105#88#108#103#112#89#114#70#106#103#44#46",5)), $oMLzKVgHrLiAtG = 'kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF'q |
Source: Inebriarti.exe.com, 00000008.00000002.2924070634.000000000154E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: For $lDMfBZXyYdklEnPNzTqemusNJakRrSoysInesZUWmdfquUcTLKIzvBh = 18 To 390^X |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1711244049.0000000000FB1000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1706584861.0000000000EC4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692968610.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1709948771.0000000000F07000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1711027703.0000000000F9A000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1705873109.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1707770480.0000000000ED4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1710380764.0000000000F79000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1711155587.0000000000FAD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: For $lDMfBZXyYdklEnPNzTqemusNJakRrSoysInesZUWmdfquUcTLKIzvBh = 18 To 39 |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp, Tt843YGUx5.exe, 00000000.00000003.1680799306.0000000003850000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1 |
Source: Bonta.exe.com, 0000000A.00000002.2926371266.0000000003AB9000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Inebriarti.exe.com, 00000005.00000003.1706584861.0000000000EC4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692968610.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1709948771.0000000000F07000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1710670447.0000000000F4B000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1705873109.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1710792928.0000000000F67000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1707770480.0000000000ED4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1706721244.0000000000ECD000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693180464.0000000000E43000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $xTAygaMnGSysza = 'UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK'N |
Source: Inebriarti.exe.com, 00000008.00000002.2927741205.0000000004773000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllw |
Source: Bonta.exe.com, 0000000A.00000002.2925494466.0000000003840000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJGX |
Source: Inebriarti.exe.com, 00000005.00000003.1706584861.0000000000EC4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692968610.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1709948771.0000000000F07000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1710670447.0000000000F4B000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1705873109.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1707770480.0000000000ED4000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1706721244.0000000000ECD000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693180464.0000000000E43000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $puvSDtqYrsfhEL = 'RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUc'' |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Switch $FtFgHgfSLDQHNz |
Source: Tt843YGUx5.exe, 00000000.00000002.2108031796.000000000051E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}d-^ |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.0000000002BCA000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.2923997739.00000000014EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $xTAygaMnGSysza = 'UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK' |
Source: Tt843YGUx5.exe, 00000000.00000003.1680945398.00000000030D9000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = 195 |
Source: Inebriarti.exe.com, 00000008.00000002.2923997739.00000000014EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $puvSDtqYrsfhEL = 'RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUc'V'r |
Source: Inebriarti.exe.com, 00000005.00000003.1746199416.0000000003B61000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.2926882914.0000000004310000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: LDMFBZXYYDKLENPNZTQEMUSNJAKRRSOYSINESZUWMDFQUUCTLKIZVBH |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00405420 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z,GetVersionExW,GetCommandLineW,GetCommandLineW,lstrlenW,GetCommandLineW,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetModuleFileNameW,_wtol,??2@YAPAXI@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetCommandLineW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetCurrentProcess,SetProcessWorkingSetSize,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,CoInitialize,lstrlenW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,GetKeyState,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetFileAttributesW,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,MessageBoxA, | 0_2_00405420 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007D696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 5_2_007D696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_007D6E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 5_2_007D6E32 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AC696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 7_2_00AC696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00AC6E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 7_2_00AC6E32 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0044696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 11_2_0044696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00446E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 11_2_00446E32 |