Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.217.208.36 |
Source: Yara match | File source: 25.3.aspnet_wp.exe.76c0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 25.3.aspnet_wp.exe.76c0000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 25.3.aspnet_wp.exe.78e0000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.aspnet_wp.exe.7080000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 41.3.aspnet_wp.exe.7c70000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.aspnet_wp.exe.7080000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 39.3.csc.exe.78a0000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.svchost.exe.4a00000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 39.3.csc.exe.7680000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 25.3.aspnet_wp.exe.76c0000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.3.aspnet_wp.exe.7420000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 41.3.aspnet_wp.exe.7c70000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.aspnet_wp.exe.7080000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.aspnet_wp.exe.72a0000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.svchost.exe.4c20000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 41.3.aspnet_wp.exe.7a50000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.3.aspnet_wp.exe.7200000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000029.00000003.1818743431.0000000007A50000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000003.1820255773.0000000007C70000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000027.00000003.1813244913.00000000078A0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000003.1814098812.00000000076C0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000003.1815614888.0000000007420000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000003.1679891251.0000000007080000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000027.00000003.1810929790.0000000007680000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000003.1680205438.00000000072A0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000003.1815228959.0000000007200000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.1691208458.0000000004C20000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.1691005457.0000000004A00000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000003.1814532754.00000000078E0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: aspnet_wp.exe PID: 7404, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: svchost.exe PID: 7512, type: MEMORYSTR |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0046CC25 | 5_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0045C09A | 5_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_00461170 | 5_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0045F13B | 5_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0046264D | 5_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0045C3DC | 5_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_00466F89 | 5_3_00466F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0046CC25 | 6_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0045C09A | 6_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_00461170 | 6_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0045F13B | 6_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0046264D | 6_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0045C3DC | 6_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_00466F89 | 6_3_00466F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0046CC25 | 14_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0045C09A | 14_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_00461170 | 14_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0045F13B | 14_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0046264D | 14_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0045C3DC | 14_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_00466F89 | 14_3_00466F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0046CC25 | 18_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0045C09A | 18_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_00461170 | 18_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0045F13B | 18_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0046264D | 18_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0045C3DC | 18_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_00466F89 | 18_3_00466F89 |
Source: C:\Windows\System32\fontdrvhost.exe | Code function: 21_2_000001D989A30C70 | 21_2_000001D989A30C70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0046CC25 | 25_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0045C09A | 25_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_00461170 | 25_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0045F13B | 25_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0046264D | 25_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0045C3DC | 25_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_00466F89 | 25_3_00466F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0046CC25 | 27_3_0046CC25 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0045C09A | 27_3_0045C09A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_00461170 | 27_3_00461170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0045F13B | 27_3_0045F13B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0046264D | 27_3_0046264D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0045C3DC | 27_3_0045C3DC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_00466F89 | 27_3_00466F89 |
Source: unknown | Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",#1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,0JtuASf5KRJM1m7CP2DvOGzERQL | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",#1 | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7396 -s 468 | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7404 -s 588 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,0jAhJvcYIPDZ24PSXVYavD8K | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7628 -s 464 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,173IY60Q | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7732 -s 464 | |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",0JtuASf5KRJM1m7CP2DvOGzERQL | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",0jAhJvcYIPDZ24PSXVYavD8K | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",173IY60Q | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",zTUCjK713b | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",zBSEjmNmvbnuGbbjL67CPQatDx8WVg | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yx6HRSAvXu71cki2UP | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",ymPj70lSkYuvU1IX343v | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yWHf8uRZL | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yLhJlDeDsE13qMVifgCiU6Sio | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yLdl32GLsBqQrfNqVsRCiWV7d8e6 | |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,0JtuASf5KRJM1m7CP2DvOGzERQL | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,0jAhJvcYIPDZ24PSXVYavD8K | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\vstdlib_s64.dll.dll,173IY60Q | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",0JtuASf5KRJM1m7CP2DvOGzERQL | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",0jAhJvcYIPDZ24PSXVYavD8K | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",173IY60Q | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",zTUCjK713b | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",zBSEjmNmvbnuGbbjL67CPQatDx8WVg | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yx6HRSAvXu71cki2UP | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",ymPj70lSkYuvU1IX343v | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yWHf8uRZL | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yLhJlDeDsE13qMVifgCiU6Sio | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",yLdl32GLsBqQrfNqVsRCiWV7d8e6 | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7396 -s 468 | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_004719B4 push ecx; ret | 5_3_004719C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F525D push es; ret | 5_3_067F5264 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F0F6A push eax; ret | 5_3_067F0F75 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F3FD4 push ss; retf | 5_3_067F3FF5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F3F89 push edi; iretd | 5_3_067F3F96 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F2C39 push ecx; ret | 5_3_067F2C59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F10F9 push FFFFFF82h; iretd | 5_3_067F10FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F44F9 push edx; retf | 5_3_067F44FC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F28EC push edi; ret | 5_3_067F28F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F4D5E push esi; ret | 5_3_067F4D69 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_067F21DC push eax; ret | 5_3_067F21DD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F525D push es; ret | 5_2_067F5264 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F0F6A push eax; ret | 5_2_067F0F75 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F3FD4 push ss; retf | 5_2_067F3FF5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F3F89 push edi; iretd | 5_2_067F3F96 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F2C39 push ecx; ret | 5_2_067F2C59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F10F9 push FFFFFF82h; iretd | 5_2_067F10FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F44F9 push edx; retf | 5_2_067F44FC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F28EC push edi; ret | 5_2_067F28F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F4D5E push esi; ret | 5_2_067F4D69 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_2_067F21DC push eax; ret | 5_2_067F21DD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_004719B4 push ecx; ret | 6_3_004719C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E525D push es; ret | 6_3_065E5264 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E0F6A push eax; ret | 6_3_065E0F75 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E3FD4 push ss; retf | 6_3_065E3FF5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E3F89 push edi; iretd | 6_3_065E3F96 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E2C39 push ecx; ret | 6_3_065E2C59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E10F9 push FFFFFF82h; iretd | 6_3_065E10FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E44F9 push edx; retf | 6_3_065E44FC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E28EC push edi; ret | 6_3_065E28F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_065E4D5E push esi; ret | 6_3_065E4D69 |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 5_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 5_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 5_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 5_3_00464B0C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 6_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 6_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 6_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 6_3_00464B0C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 14_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 14_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 14_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 14_3_00464B0C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 18_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 18_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 18_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 18_3_00464B0C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 25_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 25_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 25_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 25_3_00464B0C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_0045800F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 27_3_0045800F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_00457D4D IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 27_3_00457D4D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Code function: 27_3_00464B0C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 27_3_00464B0C |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 49DA008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4702008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4FF1008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4C7F008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4E0C008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4868008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 51A8008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe base: 4C82008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: ADF008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 51D3008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 46E2008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 514B008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4820008 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 400000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 401000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 473000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 479000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47A000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 47B000 | |
Source: C:\Windows\System32\rundll32.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe base: 4FD7008 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\vstdlib_s64.dll.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe" | Jump to behavior |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\rundll32.exe | Process created: unknown unknown | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe | Process created: unknown unknown | |