Click to jump to signature section
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD884D0 BCryptGenRandom,SystemFunction036,BCryptGenRandom,SystemFunction036,BCryptGenRandom,SystemFunction036,BCryptGenRandom,SystemFunction036, | 0_2_00007FF7FAD884D0 |
Source: 55hj0aeSzk.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD735B0 WakeByAddressSingle,NtCancelIoFileEx,RtlNtStatusToDosError,NtDeviceIoControlFile,RtlNtStatusToDosError,WakeByAddressSingle,WakeByAddressSingle,WakeByAddressSingle,WakeByAddressSingle, | 0_2_00007FF7FAD735B0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD72BC0 NtCancelIoFileEx,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,RtlNtStatusToDosError, | 0_2_00007FF7FAD72BC0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD735B0: WakeByAddressSingle,NtCancelIoFileEx,RtlNtStatusToDosError,NtDeviceIoControlFile,RtlNtStatusToDosError,WakeByAddressSingle,WakeByAddressSingle,WakeByAddressSingle,WakeByAddressSingle, | 0_2_00007FF7FAD735B0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE57760 | 0_2_00007FF7FAE57760 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE55430 | 0_2_00007FF7FAE55430 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD735B0 | 0_2_00007FF7FAD735B0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD81580 | 0_2_00007FF7FAD81580 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE4E580 | 0_2_00007FF7FAE4E580 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE48AF0 | 0_2_00007FF7FAE48AF0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE59E40 | 0_2_00007FF7FAE59E40 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FADA9400 | 0_2_00007FF7FADA9400 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD8D410 | 0_2_00007FF7FAD8D410 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACF1000 | 0_2_00007FF7FACF1000 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE3EBD0 | 0_2_00007FF7FAE3EBD0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD893D0 | 0_2_00007FF7FAD893D0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE717C0 | 0_2_00007FF7FAE717C0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE477B0 | 0_2_00007FF7FAE477B0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACFE3CA | 0_2_00007FF7FACFE3CA |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE3FF70 | 0_2_00007FF7FAE3FF70 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD3B760 | 0_2_00007FF7FAD3B760 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACFDB80 | 0_2_00007FF7FACFDB80 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE34B60 | 0_2_00007FF7FAE34B60 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FADACB40 | 0_2_00007FF7FADACB40 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACF2B50 | 0_2_00007FF7FACF2B50 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE47B30 | 0_2_00007FF7FAE47B30 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACFC740 | 0_2_00007FF7FACFC740 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD6D730 | 0_2_00007FF7FAD6D730 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD018DB | 0_2_00007FF7FAD018DB |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FADB30E0 | 0_2_00007FF7FADB30E0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE730E0 | 0_2_00007FF7FAE730E0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD004F7 | 0_2_00007FF7FAD004F7 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE5A4D0 | 0_2_00007FF7FAE5A4D0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE720D0 | 0_2_00007FF7FAE720D0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD6B4D0 | 0_2_00007FF7FAD6B4D0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD6D4B0 | 0_2_00007FF7FAD6D4B0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE70C90 | 0_2_00007FF7FAE70C90 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD8A060 | 0_2_00007FF7FAD8A060 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE78470 | 0_2_00007FF7FAE78470 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACFA030 | 0_2_00007FF7FACFA030 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD6F450 | 0_2_00007FF7FAD6F450 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD87020 | 0_2_00007FF7FAD87020 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD3BC30 | 0_2_00007FF7FAD3BC30 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD85830 | 0_2_00007FF7FAD85830 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FADB35E0 | 0_2_00007FF7FADB35E0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACFCE00 | 0_2_00007FF7FACFCE00 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE735E0 | 0_2_00007FF7FAE735E0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE3F970 | 0_2_00007FF7FAE3F970 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE5E130 | 0_2_00007FF7FAE5E130 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE71130 | 0_2_00007FF7FAE71130 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD016DF | 0_2_00007FF7FAD016DF |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD3DB10 | 0_2_00007FF7FAD3DB10 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE72B00 | 0_2_00007FF7FAE72B00 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE77F00 | 0_2_00007FF7FAE77F00 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD8DEE0 | 0_2_00007FF7FAD8DEE0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD3BEF0 | 0_2_00007FF7FAD3BEF0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE586E0 | 0_2_00007FF7FAE586E0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACF22D0 | 0_2_00007FF7FACF22D0 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD82280 | 0_2_00007FF7FAD82280 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD3CA90 | 0_2_00007FF7FAD3CA90 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD2DA60 | 0_2_00007FF7FAD2DA60 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE4C670 | 0_2_00007FF7FAE4C670 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE3EE60 | 0_2_00007FF7FAE3EE60 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD87670 | 0_2_00007FF7FAD87670 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAD03634 | 0_2_00007FF7FAD03634 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FACF4630 | 0_2_00007FF7FACF4630 |
Source: unknown | Process created: C:\Users\user\Desktop\55hj0aeSzk.exe "C:\Users\user\Desktop\55hj0aeSzk.exe" |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Section loaded: cryptnet.dll | Jump to behavior |
Source: 55hj0aeSzk.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: 55hj0aeSzk.exe, 00000000.00000002.3389244899.0000016F65363000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY\context.pe32c VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY\context.pe32c VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY\context.pe32c VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY\context.pe32c VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY\context.pe32c VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Queries volume information: C:\PE32-KEY VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\55hj0aeSzk.exe | Code function: 0_2_00007FF7FAE46030 WSASocketW,WSAGetLastError,WSASocketW,SetHandleInformation,GetLastError,closesocket,bind,WSAGetLastError,closesocket,WSAGetLastError, | 0_2_00007FF7FAE46030 |