Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409054 ??2@YAPAXI@Z,FindFirstFileW,FindClose, | 0_2_00409054 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00403186 FindFirstFileW,FindClose,SetLastError,CompareFileTime, | 0_2_00403186 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402A8E FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402A8E |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402B9F FindFirstFileW,FindClose,SetFileAttributesW,DeleteFileW, | 0_2_00402B9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6494A GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_00D6494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D64005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00D64005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00D6C2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_00D6CD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6CD14 FindFirstFileW,FindClose, | 5_2_00D6CD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00D6F5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00D6F735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00D6FA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D63CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00D63CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F494A GetFileAttributesW,FindFirstFileW,FindClose, | 7_2_005F494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_005F4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_005FC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FCD14 FindFirstFileW,FindClose, | 7_2_005FCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 7_2_005FCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_005FF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_005FF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_005FFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_005F3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_008A494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_008A4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_008AC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_008ACD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008ACD14 FindFirstFileW,FindClose, | 11_2_008ACD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_008AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_008AF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_008AFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_008A3CE2 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000002.1722181819.0000000000DC9000.00000002.00000001.01000000.00000005.sdmp, Bonta.exe.com, 00000007.00000002.1702099669.0000000000659000.00000002.00000001.01000000.00000006.sdmp, Inebriarti.exe.com, 00000008.00000000.1673480225.0000000000DC9000.00000002.00000001.01000000.00000005.sdmp, Bonta.exe.com, 0000000A.00000000.1674856331.0000000000659000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D8D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 5_2_00D8D164 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_0061D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 7_2_0061D164 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008CD164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 11_2_008CD164 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00405420 | 0_2_00405420 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040A840 | 0_2_0040A840 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00413821 | 0_2_00413821 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_004189E1 | 0_2_004189E1 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040A1A0 | 0_2_0040A1A0 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418200 | 0_2_00418200 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040EA30 | 0_2_0040EA30 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418ABB | 0_2_00418ABB |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409B50 | 0_2_00409B50 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040BB80 | 0_2_0040BB80 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418D53 | 0_2_00418D53 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409D00 | 0_2_00409D00 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040AF00 | 0_2_0040AF00 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_0040AF04 | 0_2_0040AF04 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D0B020 | 5_2_00D0B020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D094E0 | 5_2_00D094E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D09C80 | 5_2_00D09C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D223F5 | 5_2_00D223F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D88400 | 5_2_00D88400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D36502 | 5_2_00D36502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D0E6F0 | 5_2_00D0E6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D3265E | 5_2_00D3265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2282A | 5_2_00D2282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D389BF | 5_2_00D389BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D36A74 | 5_2_00D36A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D80A3A | 5_2_00D80A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D10BE0 | 5_2_00D10BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D5EDB2 | 5_2_00D5EDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2CD51 | 5_2_00D2CD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D80EB7 | 5_2_00D80EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D68E44 | 5_2_00D68E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D36FE6 | 5_2_00D36FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D233B7 | 5_2_00D233B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D1D45D | 5_2_00D1D45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2F409 | 5_2_00D2F409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D216B4 | 5_2_00D216B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D0F6A0 | 5_2_00D0F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D01663 | 5_2_00D01663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D1F628 | 5_2_00D1F628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D278C3 | 5_2_00D278C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2DBA5 | 5_2_00D2DBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D21BA8 | 5_2_00D21BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D39CE5 | 5_2_00D39CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D1DD28 | 5_2_00D1DD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2BFD6 | 5_2_00D2BFD6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D21FC0 | 5_2_00D21FC0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_0059B020 | 7_2_0059B020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005994E0 | 7_2_005994E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00599C80 | 7_2_00599C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B23F5 | 7_2_005B23F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00618400 | 7_2_00618400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C6502 | 7_2_005C6502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C265E | 7_2_005C265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_0059E6F0 | 7_2_0059E6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B282A | 7_2_005B282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C89BF | 7_2_005C89BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C6A74 | 7_2_005C6A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00610A3A | 7_2_00610A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005A0BE0 | 7_2_005A0BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BCD51 | 7_2_005BCD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005EEDB2 | 7_2_005EEDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F8E44 | 7_2_005F8E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00610EB7 | 7_2_00610EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C6FE6 | 7_2_005C6FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B33B7 | 7_2_005B33B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005AD45D | 7_2_005AD45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BF409 | 7_2_005BF409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00591663 | 7_2_00591663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005AF628 | 7_2_005AF628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B16B4 | 7_2_005B16B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_0059F6A0 | 7_2_0059F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B78C3 | 7_2_005B78C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B1BA8 | 7_2_005B1BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BDBA5 | 7_2_005BDBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005C9CE5 | 7_2_005C9CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005ADD28 | 7_2_005ADD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BBFD6 | 7_2_005BBFD6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B1FC0 | 7_2_005B1FC0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0084B020 | 11_2_0084B020 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008494E0 | 11_2_008494E0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00849C80 | 11_2_00849C80 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008623F5 | 11_2_008623F5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008C8400 | 11_2_008C8400 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00876502 | 11_2_00876502 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0084E6F0 | 11_2_0084E6F0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0087265E | 11_2_0087265E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086282A | 11_2_0086282A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008789BF | 11_2_008789BF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008C0A3A | 11_2_008C0A3A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00876A74 | 11_2_00876A74 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00850BE0 | 11_2_00850BE0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0089EDB2 | 11_2_0089EDB2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086CD51 | 11_2_0086CD51 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008C0EB7 | 11_2_008C0EB7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A8E44 | 11_2_008A8E44 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00876FE6 | 11_2_00876FE6 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008633B7 | 11_2_008633B7 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086F409 | 11_2_0086F409 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0085D45D | 11_2_0085D45D |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0084F6A0 | 11_2_0084F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008616B4 | 11_2_008616B4 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0085F628 | 11_2_0085F628 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00841663 | 11_2_00841663 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008678C3 | 11_2_008678C3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086DBA5 | 11_2_0086DBA5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00861BA8 | 11_2_00861BA8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00879CE5 | 11_2_00879CE5 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0085DD28 | 11_2_0085DD28 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00861FC0 | 11_2_00861FC0 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086BFD6 | 11_2_0086BFD6 |
Source: unknown | Process created: C:\Users\user\Desktop\Tt843YGUx5.exe "C:\Users\user\Desktop\Tt843YGUx5.exe" | |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd < Seminato.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com Inebriarti.exe.com A | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com Bonta.exe.com m | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com A | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com m | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com Pensiero.exe.com E | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 30 | |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com E | |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd < Seminato.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com Inebriarti.exe.com A | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com Bonta.exe.com m | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V /R "^jFsHerEbljXpXySesHEeeiaEbuspVTxTkpsgNBbkUmDsXXeCDHjpLUEthNpWLcCdRtXONEgPpaiDDqGArPGhHlidFhwqaBAmWhASZgPYzbqaMqAjuJSWPfJHXGpA$" Pure.vstm | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com Pensiero.exe.com E | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 30 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com A | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com m | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com E | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7F5C pushfd ; ret | 0_3_024C7FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7F5C pushfd ; ret | 0_3_024C7FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7D9F push ds; retf | 0_3_024C7DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7D9F push ds; retf | 0_3_024C7DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C8090 push ecx; retf 0015h | 0_3_024C8094 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C8090 push ecx; retf 0015h | 0_3_024C8094 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7F5C pushfd ; ret | 0_3_024C7FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7F5C pushfd ; ret | 0_3_024C7FBC |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7D9F push ds; retf | 0_3_024C7DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C7D9F push ds; retf | 0_3_024C7DA5 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C8090 push ecx; retf 0015h | 0_3_024C8094 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_3_024C8090 push ecx; retf 0015h | 0_3_024C8094 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00418690 push eax; ret | 0_2_004186BE |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2E93F push edi; ret | 5_2_00D2E941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2EA58 push esi; ret | 5_2_00D2EA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D68A4A push FFFFFF8Bh; iretd | 5_2_00D68A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D1CBDB push eax; retf | 5_2_00D1CBF8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D28B75 push ecx; ret | 5_2_00D28B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2EC33 push esi; ret | 5_2_00D2EC35 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D2ED1C push edi; ret | 5_2_00D2ED1E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BE93F push edi; ret | 7_2_005BE941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BEA58 push esi; ret | 7_2_005BEA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F8A4A push FFFFFF8Bh; iretd | 7_2_005F8A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005B8B75 push ecx; ret | 7_2_005B8B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005ACBF1 push eax; retf | 7_2_005ACBF8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BEC33 push esi; ret | 7_2_005BEC35 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005BED1C push edi; ret | 7_2_005BED1E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086E93F push edi; ret | 11_2_0086E941 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A8A4A push FFFFFF8Bh; iretd | 11_2_008A8A4C |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_0086EA58 push esi; ret | 11_2_0086EA5A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00868B75 push ecx; ret | 11_2_00868B88 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D859B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 5_2_00D859B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D15EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 5_2_00D15EDA |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_006159B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 7_2_006159B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005A5EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 7_2_005A5EDA |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008C59B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 11_2_008C59B3 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_00855EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 11_2_00855EDA |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00409054 ??2@YAPAXI@Z,FindFirstFileW,FindClose, | 0_2_00409054 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00403186 FindFirstFileW,FindClose,SetLastError,CompareFileTime, | 0_2_00403186 |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402A8E FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402A8E |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00402B9F FindFirstFileW,FindClose,SetFileAttributesW,DeleteFileW, | 0_2_00402B9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6494A GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_00D6494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D64005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00D64005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00D6C2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_00D6CD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6CD14 FindFirstFileW,FindClose, | 5_2_00D6CD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00D6F5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00D6F735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D6FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00D6FA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D63CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00D63CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F494A GetFileAttributesW,FindFirstFileW,FindClose, | 7_2_005F494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_005F4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_005FC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FCD14 FindFirstFileW,FindClose, | 7_2_005FCD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 7_2_005FCD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_005FF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 7_2_005FF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005FFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 7_2_005FFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_005F3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 7_2_005F3CE2 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_008A494A |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_008A4005 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_008AC2FF |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_008ACD9F |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008ACD14 FindFirstFileW,FindClose, | 11_2_008ACD14 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_008AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_008AF735 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_008AFA36 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_008A3CE2 |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1= |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692965308.0000000001B6F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1691680402.0000000001AF8000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692718915.0000000001B66000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693946637.0000000001BED000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1680075930.0000000001ACE000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692137637.0000000001B4F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693241062.0000000001B86000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.3531569353.0000000001820000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $puvSDtqYrsfhEL = 'RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUc' |
Source: Inebriarti.exe.com, 00000005.00000003.1701733792.0000000004655000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUcG |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1A |
Source: Bonta.exe.com, 0000000A.00000002.3533267635.0000000003EB0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJG |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1680075930.0000000001ACE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $mUnGEjvcQyyHiw = Execute(rETgxIUQ("88#121#119#110#115#108#78#120#75#113#116#102#121#45#44#111#109#115#90#105#88#108#103#112#89#114#70#106#103#44#46",5)), $oMLzKVgHrLiAtG = 'kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF' |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1693025789.0000000001411000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 0000000A.00000002.3531052690.00000000014DF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $VdwHnUJpYBHGiro = Execute(GKHRXxdEq("92_125_123_114_119_112_82_124_79_117_120_106_125_49_48_77_88_78_126_116_116_131_76_92_48_50",9)), $XDDiCUzGlnMH = 'ImcUYqPiljrtfCXuiybhGfsGnP' |
Source: Inebriarti.exe.com, 00000008.00000002.3532822784.000000000414A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF10#102#113#45 |
Source: Inebriarti.exe.com, 00000005.00000003.1701733792.0000000004655000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000008.00000002.3533628498.0000000004463000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK |
Source: Bonta.exe.com, 00000007.00000003.1695624391.00000000039C0000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1695897223.00000000039C0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ImcUYqPiljrtfCXuiybhGfsGnPvxGBdPPnzWJUxsFDLlSNrVKnaTijmL |
Source: Inebriarti.exe.com, 00000005.00000003.1700695130.00000000047C1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: LDMFBZXYYDKLENPNZTQEMUSNJAKRRSOYSINESZUWMDFQUUCTLKIZVBH^ |
Source: Tt843YGUx5.exe, 00000000.00000003.1666277080.0000000003850000.00000004.00001000.00020000.00000000.sdmp, Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp, Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp, Pensiero.exe.com, 0000000B.00000003.1699394881.0000000001A2E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $VjItThBcFgJSTh = Execute(ekrSXFezU("71#117#108#121#104#74#104#119#86#104#117#108#100#111#43#42#92#122#80#120#74#102#88#111#93#42#44",3)), $LHtIufRxUd = 'rAAViyZFlUnFeoHWSZCenyXOWRCUyyhgfSUBjlm' |
Source: Inebriarti.exe.com, 00000005.00000003.1692965308.0000000001B6F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1691680402.0000000001AF8000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692718915.0000000001B66000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693946637.0000000001BED000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1680075930.0000000001ACE000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692137637.0000000001B4F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1694222280.0000000001C06000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693241062.0000000001B86000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $xTAygaMnGSysza = 'UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK'r+ |
Source: Inebriarti.exe.com, 00000008.00000002.3531569353.0000000001820000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $xTAygaMnGSysza = 'UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK''@ |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1691571665.0000000001347000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1689996334.00000000012F4000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1690692557.000000000132A000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1692063083.000000000138C000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1692460284.00000000013EF000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1693445024.00000000013F4000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1688117940.00000000012CF000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1691502189.0000000001346000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1690777147.000000000133A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $DxgKjzXtlDLONYMZ = 'VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJG' |
Source: Inebriarti.exe.com, 00000008.00000002.3535027668.0000000004A38000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllFhIV |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1694655066.0000000001C1A000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1695215897.0000000001C4E000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692965308.0000000001B6F000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1691680402.0000000001AF8000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692718915.0000000001B66000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1695971445.0000000001C52000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1693946637.0000000001BED000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1680075930.0000000001ACE000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1692137637.0000000001B4F000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: For $lDMfBZXyYdklEnPNzTqemusNJakRrSoysInesZUWmdfquUcTLKIzvBh = 18 To 39 |
Source: Inebriarti.exe.com, 00000008.00000002.3533628498.0000000004463000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: RPPoXblPCCcjAMnWzIKfyWHmssVRhgFSwWmgXhfRYsTdoRmjEcVFUcN |
Source: Tt843YGUx5.exe, 00000000.00000003.1666277080.0000000003850000.00000004.00001000.00020000.00000000.sdmp, Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp, Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1 |
Source: Bonta.exe.com, 0000000A.00000002.3533799202.0000000004103000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1` |
Source: Inebriarti.exe.com, 00000008.00000002.3534018742.00000000045E0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: LDMFBZXYYDKLENPNZTQEMUSNJAKRRSOYSINESZUWMDFQUUCTLKIZVBH#n |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Switch $FtFgHgfSLDQHNz |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.0000000002C00000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $xTAygaMnGSysza = 'UGEkkLaFjAXjVGXLQawHGZdbjwhEqMURhOrQFTVBwhgFsuRRJifZsK' |
Source: Tt843YGUx5.exe, 00000000.00000003.1666418994.000000000310F000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = 195 |
Source: Inebriarti.exe.com, 00000005.00000003.1705813854.000000000438B000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1706025656.000000000438B000.00000004.00000020.00020000.00000000.sdmp, Inebriarti.exe.com, 00000005.00000003.1704634138.000000000438B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF02#121#45#44# |
Source: Inebriarti.exe.com, 00000008.00000002.3531188326.0000000001720000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Local $mUnGEjvcQyyHiw = Execute(rETgxIUQ("88#121#119#110#115#108#78#120#75#113#116#102#121#45#44#111#109#115#90#105#88#108#103#112#89#114#70#106#103#44#46",5)), $oMLzKVgHrLiAtG = 'kImZXeDRqjFLvNVshxWmCEEFWYFxpoalRvHQqemUF'PY |
Source: Bonta.exe.com, 00000007.00000003.1695528982.0000000003A5D000.00000004.00000020.00020000.00000000.sdmp, Bonta.exe.com, 00000007.00000003.1695402603.0000000003A4C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VNswdqkJHGRvmueigEoCbcbzzRZsYHefjSEKYHhxeqEMuIKbJGpaIn |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = $FtFgHgfSLDQHNz + 1& |
Source: Bonta.exe.com, 0000000A.00000002.3532962197.0000000003D70000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ImcUYqPiljrtfCXuiybhGfsGnP |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $FtFgHgfSLDQHNz = 195qPv |
Source: Tt843YGUx5.exe, 00000000.00000002.2061339840.0000000000728000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}z |
Source: Pensiero.exe.com, 0000000B.00000003.1698834848.00000000019CC000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Switch $FtFgHgfSLDQHNzI |
Source: C:\Users\user\Desktop\Tt843YGUx5.exe | Code function: 0_2_00405420 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z,GetVersionExW,GetCommandLineW,GetCommandLineW,lstrlenW,GetCommandLineW,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetModuleFileNameW,_wtol,??2@YAPAXI@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetCommandLineW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetCurrentProcess,SetProcessWorkingSetSize,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,CoInitialize,lstrlenW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,GetKeyState,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetFileAttributesW,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,MessageBoxA, | 0_2_00405420 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D7696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 5_2_00D7696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Inebriarti.exe.com | Code function: 5_2_00D76E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 5_2_00D76E32 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_0060696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 7_2_0060696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Bonta.exe.com | Code function: 7_2_00606E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 7_2_00606E32 |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008B696E socket,WSAGetLastError,bind,listen,WSAGetLastError,closesocket, | 11_2_008B696E |
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\Pensiero.exe.com | Code function: 11_2_008B6E32 socket,WSAGetLastError,bind,WSAGetLastError,closesocket, | 11_2_008B6E32 |