Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 0_2_01310869 | 0_2_01310869 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 0_2_013135F8 | 0_2_013135F8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 0_2_01311B38 | 0_2_01311B38 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015EC530 | 3_2_015EC530 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015E9480 | 3_2_015E9480 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015E19B8 | 3_2_015E19B8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015EC521 | 3_2_015EC521 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015E2DD1 | 3_2_015E2DD1 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_015E946F | 3_2_015E946F |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B26138 | 3_2_05B26138 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2BC60 | 3_2_05B2BC60 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2AF00 | 3_2_05B2AF00 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B289E0 | 3_2_05B289E0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B28588 | 3_2_05B28588 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B24520 | 3_2_05B24520 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2450F | 3_2_05B2450F |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B28579 | 3_2_05B28579 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27428 | 3_2_05B27428 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27418 | 3_2_05B27418 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2F458 | 3_2_05B2F458 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2F448 | 3_2_05B2F448 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2E750 | 3_2_05B2E750 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2E740 | 3_2_05B2E740 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B25680 | 3_2_05B25680 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2566F | 3_2_05B2566F |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2E180 | 3_2_05B2E180 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B26133 | 3_2_05B26133 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B28130 | 3_2_05B28130 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B28120 | 3_2_05B28120 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2F000 | 3_2_05B2F000 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B213A8 | 3_2_05B213A8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B20330 | 3_2_05B20330 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B20320 | 3_2_05B20320 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B25228 | 3_2_05B25228 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2521A | 3_2_05B2521A |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B24DD0 | 3_2_05B24DD0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B24DC0 | 3_2_05B24DC0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B20CD8 | 3_2_05B20CD8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27CD8 | 3_2_05B27CD8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27CC8 | 3_2_05B27CC8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2EFF0 | 3_2_05B2EFF0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B26FD0 | 3_2_05B26FD0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B26FC3 | 3_2_05B26FC3 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B289D0 | 3_2_05B289D0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B24978 | 3_2_05B24978 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B24969 | 3_2_05B24969 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2F8B0 | 3_2_05B2F8B0 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2F8A1 | 3_2_05B2F8A1 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27880 | 3_2_05B27880 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B27871 | 3_2_05B27871 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2EBA8 | 3_2_05B2EBA8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B2EB98 | 3_2_05B2EB98 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B20AB8 | 3_2_05B20AB8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B25AD8 | 3_2_05B25AD8 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Code function: 3_2_05B25ACA | 3_2_05B25ACA |
Source: 3.2.pfYNBAkPIwsCPTS.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 3.2.pfYNBAkPIwsCPTS.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.pfYNBAkPIwsCPTS.exe.488a828.6.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000003.00000002.3288037387.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.2053501273.000000000488A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: pfYNBAkPIwsCPTS.exe PID: 1520, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: pfYNBAkPIwsCPTS.exe PID: 3648, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, DOVDxC40w7qtM1QNrD.cs | High entropy of concatenated method names: 'Wu2VmOnOL8', 'yHHVJBq03n', 'lE2VcRs50P', 'zNqVqNyW1H', 'oKaVxQ0cmT', 'r1HV0xDaeA', 'jElV907MuL', 'r6gVHST0yR', 'Bu9Vn9NVDq', 'ChfVGVCy1S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, PrldAfseb0NH1BGFVk.cs | High entropy of concatenated method names: 'OvckQOdWW', 'Jks5dVb1q', 'UNfBw2IpZ', 'rkMuH33if', 'urnFFSQa2', 'OEjNDX8WT', 'ua6Fjl8t4gs3cSYcGy', 'ry1ivQasPWPfXCeBGu', 'mfayQ5i8C', 'b6dUMqKT6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, QwZ3f3P9Zf9qbQp0QC.cs | High entropy of concatenated method names: 'NBJVp8k6Zi', 'DtHVTbS9ff', 'RC2VVLmSdj', 'jcVVv8KWSw', 'OgaVQrXYMm', 'poQV8kXj9u', 'Dispose', 'TMmyj95HPi', 'qbiyfrys9G', 'ggFylHksZA' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, RSR36c10sBGNp6disf.cs | High entropy of concatenated method names: 'bDVUlvBGoX', 'e5QUd1XXKb', 'rDIUaPloQ8', 'Oi2URWrLyv', 'DtbUVPIlTY', 'FyEU3yHFXN', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, jS0UcDJVh6rmgcft7e.cs | High entropy of concatenated method names: 'Dbl7ltCJJBbSRpHXTHd', 'YV0gWjC0sYjB0dRP1ki', 'Jxnaywm3vF', 'ieyaVK4qRD', 'uL8aUWACfa', 'swhilCCrBYn5dQlkrmy', 'LfOPdJCESPIhSir8CcC', 'hVvvCWCnpohVNX63N9S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, s204SLhhU2HWvuYaHWy.cs | High entropy of concatenated method names: 'dXaU13hdEZ', 'IXuUzHLU9n', 'STrveaBhLJ', 'XMEvhkie9t', 'OgjvsMCJFI', 'X0YvZKYGBK', 'UYIvL7p9Us', 'eSrvC5A2dw', 'jpjvj3FDSg', 'pHtvfZBXSg' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, uI96sLn3Wln8bc5YhL.cs | High entropy of concatenated method names: 'KDrROBkDFY', 'mvVRYbGMhl', 'WmqRkFYZfH', 'SbhR5wLpP0', 'n3ERoatbQ9', 'r5VRBFmf2E', 'fXoRue6EXj', 'FmaRI0OMd0', 'JBeRF3pM3h', 'qP4RNrsia6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, b9RaOoFDbmF11odbmx.cs | High entropy of concatenated method names: 'f2el5SRB2Z', 'BtylBnP18p', 'txDlIfxlQ8', 'UOKlFGXaNr', 'IislpwdIsH', 'VlZlr2UhYi', 'GBIlTrOJeL', 'K32ly3GEpm', 'z51lVHpkPZ', 'w4NlUuHtnI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, AcmapKIUbKrvuF7Yhj.cs | High entropy of concatenated method names: 'NSafWUy6aE', 's6gfMHkVb8', 'kW5f7Psiys', 'VptftJVNmo', 'SZCfX6AyJV', 'AIffb3kmT9', 'w5AfP5bKA4', 'SunfisdWjB', 'oCwf44AsvV', 'n2Kf1HFbcK' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, P8mOWj6B8tJVQUh2Se.cs | High entropy of concatenated method names: 'AwjEIu1GgX', 'ulfEFwXfZU', 'rrsEm4BhBK', 'uWREJAsiN8', 'hSmEqI681U', 'yGtEx4NEXr', 'sWtE9shOpD', 'PNfEHic8dp', 'GRUEGBJVtU', 'zoZE26aMMN' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, b2iiGYbMSNgM0e5j0y.cs | High entropy of concatenated method names: 'dfHTibhdcT', 'aSyT1aN8Ti', 'XsByeGddNa', 'Mn3yh18iuF', 'mvNT2UsaF4', 'Ms4TKjOc9N', 'DrST6vqFS4', 'XCZTW71G7R', 'l6JTMoj9lb', 'gGxT7xviOI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, lG8AgVhecyX47ae3DcA.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qaxU2tDx3I', 'hAuUKKpDWK', 'J7iU6gbTYd', 'NOsUWg1P7k', 'HWhUMH1iaU', 'pEhU74gMDR', 'SSuUtmK7M5' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, JuUJQVhLGMn7A41Yphj.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'y1hAVwbGvr', 'NIrAUSpowB', 'JTjAv6AKnS', 'RMoAA9IBnA', 'pPlAQ45cGo', 'F3MADwqgsW', 'sL8A8iuWle' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, nHesDPlqQxZWSYF3El.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Opds4mGcm3', 'lOOs1XHOmE', 'Xaiszl8PHl', 'pHgZewb4vb', 'tgsZhU1C7D', 'RvgZscBBDM', 'j0ZZZnBO5f', 'QrLC2iXBCCBv3nreR6T' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, xcIsPpWk6vq4D2WcMQ.cs | High entropy of concatenated method names: 'QnPpG9jdQP', 'pLnpKpmece', 'zVwpWmwabO', 'sZMpM2YksA', 'jBbpJ7SobB', 'urjpcJj8hL', 'FtLpq9lEDc', 'hdBpxjQ8HA', 'm1pp00N0Oa', 'HLQp9Ayw78' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, QhZpTKm7t8NUl798SF.cs | High entropy of concatenated method names: 'fataC7ufHJ', 'Jmlafomr6Y', 'wWAad1dEEs', 'GXeaRdTp2J', 'psia36FgQx', 'B0udXEkyIr', 'va2dbpNZoW', 'TgKdPZOxXI', 'OysdiO9Fjm', 'BMld4WR951' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, HPFxflzTPxZqLtGoKF.cs | High entropy of concatenated method names: 'fSxUBrMOvW', 'EyZUIVaOUg', 'SYWUFtAEQJ', 'spPUmnI29F', 'RnKUJm2yVm', 'lWJUqAgi7B', 'aLEUxUkaYp', 'MDsU8At5jO', 'X2lUOHApcK', 'B6yUYttESs' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, m6meXy3dNMr2cdGc5O.cs | High entropy of concatenated method names: 'IIuZCafsYl', 'tcpZjaPNG8', 'zMVZfwyLjU', 'TFVZlpZtNa', 'Q5cZdLrRMU', 'KVhZaQqmja', 'pReZRrFbsR', 'QAQZ3gmB7W', 'T2vZwoDtAN', 'DXQZS0B8ti' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, CrD5WqLIlyhT5x3EoJ.cs | High entropy of concatenated method names: 'mB5hRcmapK', 'sbKh3rvuF7', 'BDbhSmF11o', 'hbmhgxgCCT', 'miMhpXL6hZ', 'oTKhr7t8NU', 'hFnRYAMu7lBmCe6t4Q', 'pGiveryhKiCT5LHIRs', 'qWDhhKObtW', 'B78hZ0BP9Y' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.7740000.7.raw.unpack, zpVrXTfaSyfvITxv2Z.cs | High entropy of concatenated method names: 'Dispose', 'g9qh4bQp0Q', 'pOKsJTImg8', 'HbWAXQlCfw', 'eFfh1gWUIF', 'JKphzo1SHx', 'ProcessDialogKey', 'UVIseOVDxC', 'Kw7shqtM1Q', 'FrDssWSR36' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, DOVDxC40w7qtM1QNrD.cs | High entropy of concatenated method names: 'Wu2VmOnOL8', 'yHHVJBq03n', 'lE2VcRs50P', 'zNqVqNyW1H', 'oKaVxQ0cmT', 'r1HV0xDaeA', 'jElV907MuL', 'r6gVHST0yR', 'Bu9Vn9NVDq', 'ChfVGVCy1S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, PrldAfseb0NH1BGFVk.cs | High entropy of concatenated method names: 'OvckQOdWW', 'Jks5dVb1q', 'UNfBw2IpZ', 'rkMuH33if', 'urnFFSQa2', 'OEjNDX8WT', 'ua6Fjl8t4gs3cSYcGy', 'ry1ivQasPWPfXCeBGu', 'mfayQ5i8C', 'b6dUMqKT6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, QwZ3f3P9Zf9qbQp0QC.cs | High entropy of concatenated method names: 'NBJVp8k6Zi', 'DtHVTbS9ff', 'RC2VVLmSdj', 'jcVVv8KWSw', 'OgaVQrXYMm', 'poQV8kXj9u', 'Dispose', 'TMmyj95HPi', 'qbiyfrys9G', 'ggFylHksZA' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, RSR36c10sBGNp6disf.cs | High entropy of concatenated method names: 'bDVUlvBGoX', 'e5QUd1XXKb', 'rDIUaPloQ8', 'Oi2URWrLyv', 'DtbUVPIlTY', 'FyEU3yHFXN', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, jS0UcDJVh6rmgcft7e.cs | High entropy of concatenated method names: 'Dbl7ltCJJBbSRpHXTHd', 'YV0gWjC0sYjB0dRP1ki', 'Jxnaywm3vF', 'ieyaVK4qRD', 'uL8aUWACfa', 'swhilCCrBYn5dQlkrmy', 'LfOPdJCESPIhSir8CcC', 'hVvvCWCnpohVNX63N9S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, s204SLhhU2HWvuYaHWy.cs | High entropy of concatenated method names: 'dXaU13hdEZ', 'IXuUzHLU9n', 'STrveaBhLJ', 'XMEvhkie9t', 'OgjvsMCJFI', 'X0YvZKYGBK', 'UYIvL7p9Us', 'eSrvC5A2dw', 'jpjvj3FDSg', 'pHtvfZBXSg' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, uI96sLn3Wln8bc5YhL.cs | High entropy of concatenated method names: 'KDrROBkDFY', 'mvVRYbGMhl', 'WmqRkFYZfH', 'SbhR5wLpP0', 'n3ERoatbQ9', 'r5VRBFmf2E', 'fXoRue6EXj', 'FmaRI0OMd0', 'JBeRF3pM3h', 'qP4RNrsia6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, b9RaOoFDbmF11odbmx.cs | High entropy of concatenated method names: 'f2el5SRB2Z', 'BtylBnP18p', 'txDlIfxlQ8', 'UOKlFGXaNr', 'IislpwdIsH', 'VlZlr2UhYi', 'GBIlTrOJeL', 'K32ly3GEpm', 'z51lVHpkPZ', 'w4NlUuHtnI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, AcmapKIUbKrvuF7Yhj.cs | High entropy of concatenated method names: 'NSafWUy6aE', 's6gfMHkVb8', 'kW5f7Psiys', 'VptftJVNmo', 'SZCfX6AyJV', 'AIffb3kmT9', 'w5AfP5bKA4', 'SunfisdWjB', 'oCwf44AsvV', 'n2Kf1HFbcK' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, P8mOWj6B8tJVQUh2Se.cs | High entropy of concatenated method names: 'AwjEIu1GgX', 'ulfEFwXfZU', 'rrsEm4BhBK', 'uWREJAsiN8', 'hSmEqI681U', 'yGtEx4NEXr', 'sWtE9shOpD', 'PNfEHic8dp', 'GRUEGBJVtU', 'zoZE26aMMN' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, b2iiGYbMSNgM0e5j0y.cs | High entropy of concatenated method names: 'dfHTibhdcT', 'aSyT1aN8Ti', 'XsByeGddNa', 'Mn3yh18iuF', 'mvNT2UsaF4', 'Ms4TKjOc9N', 'DrST6vqFS4', 'XCZTW71G7R', 'l6JTMoj9lb', 'gGxT7xviOI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, lG8AgVhecyX47ae3DcA.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qaxU2tDx3I', 'hAuUKKpDWK', 'J7iU6gbTYd', 'NOsUWg1P7k', 'HWhUMH1iaU', 'pEhU74gMDR', 'SSuUtmK7M5' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, JuUJQVhLGMn7A41Yphj.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'y1hAVwbGvr', 'NIrAUSpowB', 'JTjAv6AKnS', 'RMoAA9IBnA', 'pPlAQ45cGo', 'F3MADwqgsW', 'sL8A8iuWle' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, nHesDPlqQxZWSYF3El.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Opds4mGcm3', 'lOOs1XHOmE', 'Xaiszl8PHl', 'pHgZewb4vb', 'tgsZhU1C7D', 'RvgZscBBDM', 'j0ZZZnBO5f', 'QrLC2iXBCCBv3nreR6T' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, xcIsPpWk6vq4D2WcMQ.cs | High entropy of concatenated method names: 'QnPpG9jdQP', 'pLnpKpmece', 'zVwpWmwabO', 'sZMpM2YksA', 'jBbpJ7SobB', 'urjpcJj8hL', 'FtLpq9lEDc', 'hdBpxjQ8HA', 'm1pp00N0Oa', 'HLQp9Ayw78' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, QhZpTKm7t8NUl798SF.cs | High entropy of concatenated method names: 'fataC7ufHJ', 'Jmlafomr6Y', 'wWAad1dEEs', 'GXeaRdTp2J', 'psia36FgQx', 'B0udXEkyIr', 'va2dbpNZoW', 'TgKdPZOxXI', 'OysdiO9Fjm', 'BMld4WR951' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, HPFxflzTPxZqLtGoKF.cs | High entropy of concatenated method names: 'fSxUBrMOvW', 'EyZUIVaOUg', 'SYWUFtAEQJ', 'spPUmnI29F', 'RnKUJm2yVm', 'lWJUqAgi7B', 'aLEUxUkaYp', 'MDsU8At5jO', 'X2lUOHApcK', 'B6yUYttESs' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, m6meXy3dNMr2cdGc5O.cs | High entropy of concatenated method names: 'IIuZCafsYl', 'tcpZjaPNG8', 'zMVZfwyLjU', 'TFVZlpZtNa', 'Q5cZdLrRMU', 'KVhZaQqmja', 'pReZRrFbsR', 'QAQZ3gmB7W', 'T2vZwoDtAN', 'DXQZS0B8ti' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, CrD5WqLIlyhT5x3EoJ.cs | High entropy of concatenated method names: 'mB5hRcmapK', 'sbKh3rvuF7', 'BDbhSmF11o', 'hbmhgxgCCT', 'miMhpXL6hZ', 'oTKhr7t8NU', 'hFnRYAMu7lBmCe6t4Q', 'pGiveryhKiCT5LHIRs', 'qWDhhKObtW', 'B78hZ0BP9Y' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a7b598.5.raw.unpack, zpVrXTfaSyfvITxv2Z.cs | High entropy of concatenated method names: 'Dispose', 'g9qh4bQp0Q', 'pOKsJTImg8', 'HbWAXQlCfw', 'eFfh1gWUIF', 'JKphzo1SHx', 'ProcessDialogKey', 'UVIseOVDxC', 'Kw7shqtM1Q', 'FrDssWSR36' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, DOVDxC40w7qtM1QNrD.cs | High entropy of concatenated method names: 'Wu2VmOnOL8', 'yHHVJBq03n', 'lE2VcRs50P', 'zNqVqNyW1H', 'oKaVxQ0cmT', 'r1HV0xDaeA', 'jElV907MuL', 'r6gVHST0yR', 'Bu9Vn9NVDq', 'ChfVGVCy1S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, PrldAfseb0NH1BGFVk.cs | High entropy of concatenated method names: 'OvckQOdWW', 'Jks5dVb1q', 'UNfBw2IpZ', 'rkMuH33if', 'urnFFSQa2', 'OEjNDX8WT', 'ua6Fjl8t4gs3cSYcGy', 'ry1ivQasPWPfXCeBGu', 'mfayQ5i8C', 'b6dUMqKT6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, QwZ3f3P9Zf9qbQp0QC.cs | High entropy of concatenated method names: 'NBJVp8k6Zi', 'DtHVTbS9ff', 'RC2VVLmSdj', 'jcVVv8KWSw', 'OgaVQrXYMm', 'poQV8kXj9u', 'Dispose', 'TMmyj95HPi', 'qbiyfrys9G', 'ggFylHksZA' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, RSR36c10sBGNp6disf.cs | High entropy of concatenated method names: 'bDVUlvBGoX', 'e5QUd1XXKb', 'rDIUaPloQ8', 'Oi2URWrLyv', 'DtbUVPIlTY', 'FyEU3yHFXN', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, jS0UcDJVh6rmgcft7e.cs | High entropy of concatenated method names: 'Dbl7ltCJJBbSRpHXTHd', 'YV0gWjC0sYjB0dRP1ki', 'Jxnaywm3vF', 'ieyaVK4qRD', 'uL8aUWACfa', 'swhilCCrBYn5dQlkrmy', 'LfOPdJCESPIhSir8CcC', 'hVvvCWCnpohVNX63N9S' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, s204SLhhU2HWvuYaHWy.cs | High entropy of concatenated method names: 'dXaU13hdEZ', 'IXuUzHLU9n', 'STrveaBhLJ', 'XMEvhkie9t', 'OgjvsMCJFI', 'X0YvZKYGBK', 'UYIvL7p9Us', 'eSrvC5A2dw', 'jpjvj3FDSg', 'pHtvfZBXSg' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, uI96sLn3Wln8bc5YhL.cs | High entropy of concatenated method names: 'KDrROBkDFY', 'mvVRYbGMhl', 'WmqRkFYZfH', 'SbhR5wLpP0', 'n3ERoatbQ9', 'r5VRBFmf2E', 'fXoRue6EXj', 'FmaRI0OMd0', 'JBeRF3pM3h', 'qP4RNrsia6' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, b9RaOoFDbmF11odbmx.cs | High entropy of concatenated method names: 'f2el5SRB2Z', 'BtylBnP18p', 'txDlIfxlQ8', 'UOKlFGXaNr', 'IislpwdIsH', 'VlZlr2UhYi', 'GBIlTrOJeL', 'K32ly3GEpm', 'z51lVHpkPZ', 'w4NlUuHtnI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, AcmapKIUbKrvuF7Yhj.cs | High entropy of concatenated method names: 'NSafWUy6aE', 's6gfMHkVb8', 'kW5f7Psiys', 'VptftJVNmo', 'SZCfX6AyJV', 'AIffb3kmT9', 'w5AfP5bKA4', 'SunfisdWjB', 'oCwf44AsvV', 'n2Kf1HFbcK' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, P8mOWj6B8tJVQUh2Se.cs | High entropy of concatenated method names: 'AwjEIu1GgX', 'ulfEFwXfZU', 'rrsEm4BhBK', 'uWREJAsiN8', 'hSmEqI681U', 'yGtEx4NEXr', 'sWtE9shOpD', 'PNfEHic8dp', 'GRUEGBJVtU', 'zoZE26aMMN' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, b2iiGYbMSNgM0e5j0y.cs | High entropy of concatenated method names: 'dfHTibhdcT', 'aSyT1aN8Ti', 'XsByeGddNa', 'Mn3yh18iuF', 'mvNT2UsaF4', 'Ms4TKjOc9N', 'DrST6vqFS4', 'XCZTW71G7R', 'l6JTMoj9lb', 'gGxT7xviOI' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, lG8AgVhecyX47ae3DcA.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qaxU2tDx3I', 'hAuUKKpDWK', 'J7iU6gbTYd', 'NOsUWg1P7k', 'HWhUMH1iaU', 'pEhU74gMDR', 'SSuUtmK7M5' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, JuUJQVhLGMn7A41Yphj.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'y1hAVwbGvr', 'NIrAUSpowB', 'JTjAv6AKnS', 'RMoAA9IBnA', 'pPlAQ45cGo', 'F3MADwqgsW', 'sL8A8iuWle' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, nHesDPlqQxZWSYF3El.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Opds4mGcm3', 'lOOs1XHOmE', 'Xaiszl8PHl', 'pHgZewb4vb', 'tgsZhU1C7D', 'RvgZscBBDM', 'j0ZZZnBO5f', 'QrLC2iXBCCBv3nreR6T' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, xcIsPpWk6vq4D2WcMQ.cs | High entropy of concatenated method names: 'QnPpG9jdQP', 'pLnpKpmece', 'zVwpWmwabO', 'sZMpM2YksA', 'jBbpJ7SobB', 'urjpcJj8hL', 'FtLpq9lEDc', 'hdBpxjQ8HA', 'm1pp00N0Oa', 'HLQp9Ayw78' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, QhZpTKm7t8NUl798SF.cs | High entropy of concatenated method names: 'fataC7ufHJ', 'Jmlafomr6Y', 'wWAad1dEEs', 'GXeaRdTp2J', 'psia36FgQx', 'B0udXEkyIr', 'va2dbpNZoW', 'TgKdPZOxXI', 'OysdiO9Fjm', 'BMld4WR951' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, HPFxflzTPxZqLtGoKF.cs | High entropy of concatenated method names: 'fSxUBrMOvW', 'EyZUIVaOUg', 'SYWUFtAEQJ', 'spPUmnI29F', 'RnKUJm2yVm', 'lWJUqAgi7B', 'aLEUxUkaYp', 'MDsU8At5jO', 'X2lUOHApcK', 'B6yUYttESs' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, m6meXy3dNMr2cdGc5O.cs | High entropy of concatenated method names: 'IIuZCafsYl', 'tcpZjaPNG8', 'zMVZfwyLjU', 'TFVZlpZtNa', 'Q5cZdLrRMU', 'KVhZaQqmja', 'pReZRrFbsR', 'QAQZ3gmB7W', 'T2vZwoDtAN', 'DXQZS0B8ti' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, CrD5WqLIlyhT5x3EoJ.cs | High entropy of concatenated method names: 'mB5hRcmapK', 'sbKh3rvuF7', 'BDbhSmF11o', 'hbmhgxgCCT', 'miMhpXL6hZ', 'oTKhr7t8NU', 'hFnRYAMu7lBmCe6t4Q', 'pGiveryhKiCT5LHIRs', 'qWDhhKObtW', 'B78hZ0BP9Y' |
Source: 0.2.pfYNBAkPIwsCPTS.exe.4a20178.4.raw.unpack, zpVrXTfaSyfvITxv2Z.cs | High entropy of concatenated method names: 'Dispose', 'g9qh4bQp0Q', 'pOKsJTImg8', 'HbWAXQlCfw', 'eFfh1gWUIF', 'JKphzo1SHx', 'ProcessDialogKey', 'UVIseOVDxC', 'Kw7shqtM1Q', 'FrDssWSR36' |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\pfYNBAkPIwsCPTS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |