Click to jump to signature section
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: StormKittyBuild (3).exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.com |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.com |
Source: global traffic | HTTP traffic detected: GET /LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13.8/lib/net40/DotNetZip.dll HTTP/1.1Host: raw.githubusercontent.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closeContent-Length: 14Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandboxStrict-Transport-Security: max-age=31536000X-Content-Type-Options: nosniffX-Frame-Options: denyX-XSS-Protection: 1; mode=blockContent-Type: text/plain; charset=utf-8X-GitHub-Request-Id: 28E5:3EAF79:B9F25D:EDF52E:67C690ECAccept-Ranges: bytesDate: Tue, 04 Mar 2025 05:34:38 GMTVia: 1.1 varnishX-Served-By: cache-nyc-kteb1890072-NYCX-Cache: MISSX-Cache-Hits: 0X-Timer: S1741066478.424978,VS0,VE38Vary: Authorization,Accept-Encoding,OriginAccess-Control-Allow-Origin: *Cross-Origin-Resource-Policy: cross-originX-Fastly-Request-ID: 739fb42c0f9cb0f77b67d436f21194d55146b407Expires: Tue, 04 Mar 2025 05:39:38 GMTSource-Age: 0 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closeContent-Length: 14Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandboxStrict-Transport-Security: max-age=31536000X-Content-Type-Options: nosniffX-Frame-Options: denyX-XSS-Protection: 1; mode=blockContent-Type: text/plain; charset=utf-8X-GitHub-Request-Id: DFF4:26D83:1491C4:1B5EC8:67C690F0Accept-Ranges: bytesDate: Tue, 04 Mar 2025 05:34:41 GMTVia: 1.1 varnishX-Served-By: cache-ewr-kewr1740045-EWRX-Cache: MISSX-Cache-Hits: 0X-Timer: S1741066481.088429,VS0,VE10Vary: Authorization,Accept-Encoding,OriginAccess-Control-Allow-Origin: *Cross-Origin-Resource-Policy: cross-originX-Fastly-Request-ID: 758b935c4a76e655d4aac35c581c74615ee9e704Expires: Tue, 04 Mar 2025 05:39:41 GMTSource-Age: 0 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closeContent-Length: 14Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandboxStrict-Transport-Security: max-age=31536000X-Content-Type-Options: nosniffX-Frame-Options: denyX-XSS-Protection: 1; mode=blockContent-Type: text/plain; charset=utf-8X-GitHub-Request-Id: DFF4:26D83:1491C4:1B5EC8:67C690F0Accept-Ranges: bytesDate: Tue, 04 Mar 2025 05:34:43 GMTVia: 1.1 varnishX-Served-By: cache-ewr-kewr1740070-EWRX-Cache: HITX-Cache-Hits: 1X-Timer: S1741066484.665054,VS0,VE1Vary: Authorization,Accept-Encoding,OriginAccess-Control-Allow-Origin: *Cross-Origin-Resource-Policy: cross-originX-Fastly-Request-ID: a1fecd2b87571823a5b8dfe69acaa27c3a0d4251Expires: Tue, 04 Mar 2025 05:39:43 GMTSource-Age: 3 |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.000000000388F000.00000004.00000800.00020000.00000000.sdmp, StormKittyBuild (3).exe, 00000000.00000002.4596446701.000000000391E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.000000000388F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=h |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.000000000388F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.00000000039B3000.00000004.00000800.00020000.00000000.sdmp, StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003A25000.00000004.00000800.00020000.00000000.sdmp, StormKittyBuild (3).exe, 00000000.00000002.4596446701.00000000039D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://raw.githubusercontent.com |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.000000000388F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: StormKittyBuild (3).exe | String found in binary or memory: https://github.com/LimerBoy/StormKitty |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/LimerBoy/StormKittyP~ |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.00000000039A0000.00000004.00000800.00020000.00000000.sdmp, StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003A25000.00000004.00000800.00020000.00000000.sdmp, StormKittyBuild (3).exe, 00000000.00000002.4596446701.00000000039D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://raw.githubusercontent.com |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://raw.githubusercontent.com/LimerBoy/StormKitty/master/StormKitty/stub/packages/AnonFileApi.1. |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://raw.githubusercontent.com/LimerBoy/StormKitty/master/StormKitty/stub/packages/DotNetZip.1.13 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49711 |
Source: unknown | Network traffic detected: HTTP traffic on port 49711 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 49713 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49713 |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: StormKittyBuild (3).exe, type: SAMPLE | Matched rule: Detects StormKitty infostealer Author: ditekSHen |
Source: 0.2.StormKittyBuild (3).exe.ef0000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects StormKitty infostealer Author: ditekSHen |
Source: 0.2.StormKittyBuild (3).exe.ef0000.0.unpack, type: UNPACKEDPE | Matched rule: Detects StormKitty infostealer Author: ditekSHen |
Source: 0.0.StormKittyBuild (3).exe.540000.0.unpack, type: UNPACKEDPE | Matched rule: Detects StormKitty infostealer Author: ditekSHen |
Source: 00000000.00000002.4596183518.0000000000EF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Detects StormKitty infostealer Author: ditekSHen |
Source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen |
Source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR | Matched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD3454089D | 0_2_00007FFD3454089D |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD345465C8 | 0_2_00007FFD345465C8 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34540568 | 0_2_00007FFD34540568 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34545E82 | 0_2_00007FFD34545E82 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD345463E5 | 0_2_00007FFD345463E5 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD3454B4CC | 0_2_00007FFD3454B4CC |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD3454B52F | 0_2_00007FFD3454B52F |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD3454BD38 | 0_2_00007FFD3454BD38 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34540500 | 0_2_00007FFD34540500 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34544DFB | 0_2_00007FFD34544DFB |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34547684 | 0_2_00007FFD34547684 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD3454B34F | 0_2_00007FFD3454B34F |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD345436FA | 0_2_00007FFD345436FA |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD345407C0 | 0_2_00007FFD345407C0 |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Code function: 0_2_00007FFD34548BBB | 0_2_00007FFD34548BBB |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596183518.0000000000EF0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameStormKitty.exe* vs StormKittyBuild (3).exe |
Source: StormKittyBuild (3).exe | Binary or memory string: OriginalFilenameStormKitty.exe* vs StormKittyBuild (3).exe |
Source: StormKittyBuild (3).exe, type: SAMPLE | Matched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty |
Source: 0.2.StormKittyBuild (3).exe.ef0000.0.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty |
Source: 0.2.StormKittyBuild (3).exe.ef0000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty |
Source: 0.0.StormKittyBuild (3).exe.540000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty |
Source: 00000000.00000002.4596183518.0000000000EF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty |
Source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions |
Source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions |
Source: StormKittyBuild (3).exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Mutant created: \Sessions\1\BaseNamedObjects\D050C29EE7B113DCFC2A93B1760766AB |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Mutant created: NULL |
Source: StormKittyBuild (3).exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: StormKittyBuild (3).exe | Virustotal: Detection: 59% |
Source: StormKittyBuild (3).exe | ReversingLabs: Detection: 65% |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Section loaded: wintypes.dll | Jump to behavior |
Source: StormKittyBuild (3).exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003998000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: SBIEDLL.DLL |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599890 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599527 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599181 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599075 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598968 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598855 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598741 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598628 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598441 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598313 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598158 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598032 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597921 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597812 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597703 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597593 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597484 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597375 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597265 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597156 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597047 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596937 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596826 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596718 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596609 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596500 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596390 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596281 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596170 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596062 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595953 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595843 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595734 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595583 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595294 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595134 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595004 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594875 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594765 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594656 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594546 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594437 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594328 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594218 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594109 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594000 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 593890 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -30437127721620741s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599527s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599181s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -599075s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598855s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598741s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598628s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598441s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598158s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -598032s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597921s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597265s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -597047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596826s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596390s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596170s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -596062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595843s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595583s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595294s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595134s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -595004s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -594000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe TID: 2836 | Thread sleep time: -593890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599890 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599527 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599181 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 599075 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598968 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598855 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598741 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598628 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598441 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598313 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598158 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 598032 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597921 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597812 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597703 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597593 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597484 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597375 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597265 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597156 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 597047 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596937 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596826 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596718 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596609 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596500 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596390 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596281 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596170 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 596062 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595953 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595843 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595734 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595583 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595294 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595134 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 595004 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594875 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594765 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594656 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594546 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594437 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594328 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594218 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594109 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 594000 | Jump to behavior |
Source: C:\Users\user\Desktop\StormKittyBuild (3).exe | Thread delayed: delay time: 593890 | Jump to behavior |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003992000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: StormKittyBuild (3).exe | Binary or memory string: qeMu0G |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VirtualMachine: |
Source: StormKittyBuild (3).exe, 00000000.00000002.4599700046.000000001E160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllc |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: Electrum |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: Jaxx5 |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Exodus\exodus.wallet |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Ethereum\keystore |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: Exodus |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: Ethereum |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Coinomi\Coinomi\wallets |
Source: StormKittyBuild (3).exe, 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Ethereum\keystore |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |
Source: Yara match | File source: 00000000.00000002.4596446701.0000000003511000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: StormKittyBuild (3).exe PID: 5768, type: MEMORYSTR |