Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.com |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.comd |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002B31000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.0000000002832000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002B31000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000027C1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/d |
Source: PI 00928292828.exe, 00000000.00000002.1701269663.00000000044B3000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2941514043.0000000000413000.00000040.00000400.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000045C3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.orgd |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://mail.mzgold.ir |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://mail.mzgold.ird |
Source: PI 00928292828.exe, 00000001.00000002.2942324299.0000000000C87000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.0000000006094000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B4000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E6C000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E30000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2943277640.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://r11.i.lencr.org/0 |
Source: PI 00928292828.exe, 00000001.00000002.2942324299.0000000000C87000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.0000000006094000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B4000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E6C000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E30000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2943277640.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://r11.o.lencr.org0# |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BC0000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000285B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.org |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BC0000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000285B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.orgd |
Source: PI 00928292828.exe, 00000000.00000002.1691908965.00000000032D1000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002B31000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1837219390.00000000031F5000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000027C1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B9000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2942324299.0000000000C87000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B4000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950672050.0000000005E73000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E30000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2943277640.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://x1.c.lencr.org/0 |
Source: PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B9000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2942324299.0000000000C87000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2950272190.00000000060B4000.00000004.00000020.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950672050.0000000005E73000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2950213670.0000000005E30000.00000004.00000020.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2943277640.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://x1.i.lencr.org/0 |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002C48000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.00000000028E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: PI 00928292828.exe, 00000000.00000002.1701269663.00000000044B3000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2941514043.0000000000413000.00000040.00000400.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000045C3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot-/sendDocument?chat_id= |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: PI 00928292828.exe, 00000000.00000002.1701269663.00000000044B3000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, PI 00928292828.exe, 00000001.00000002.2941514043.0000000000413000.00000040.00000400.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000045C3000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189d |
Source: PI 00928292828.exe, 00000001.00000002.2945608145.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000004.00000002.2945164614.000000000283E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189l |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, PI 00928292828.exe, 00000000.00000002.1691908965.00000000032D1000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1837219390.00000000031F5000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: PI 00928292828.exe, 00000000.00000002.1704203575.0000000005F40000.00000004.08000000.00040000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.00000000043A7000.00000004.00000800.00020000.00000000.sdmp, skype.exe, 00000003.00000002.1859555653.0000000004455000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_03161840 | 0_2_03161840 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_03161CB8 | 0_2_03161CB8 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_0316B5F0 | 0_2_0316B5F0 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_0316B5E1 | 0_2_0316B5E1 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_03161A41 | 0_2_03161A41 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_0316BF73 | 0_2_0316BF73 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_0316BF80 | 0_2_0316BF80 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_03161CA7 | 0_2_03161CA7 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066EF708 | 0_2_066EF708 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066EF9C8 | 0_2_066EF9C8 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066EE610 | 0_2_066EE610 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066EE078 | 0_2_066EE078 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066D0040 | 0_2_066D0040 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 0_2_066D0021 | 0_2_066D0021 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_00EFC548 | 1_2_00EFC548 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_00EF2DD1 | 1_2_00EF2DD1 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_00EF9490 | 1_2_00EF9490 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_00EFC539 | 1_2_00EFC539 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_00EF947F | 1_2_00EF947F |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_06965E0C | 1_2_06965E0C |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_0696B709 | 1_2_0696B709 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_06966C71 | 1_2_06966C71 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_06963200 | 1_2_06963200 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Code function: 1_2_06964A60 | 1_2_06964A60 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_01681840 | 3_2_01681840 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_01681CB8 | 3_2_01681CB8 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0168B5E1 | 3_2_0168B5E1 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0168B5F0 | 3_2_0168B5F0 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_01681A41 | 3_2_01681A41 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_01681CA7 | 3_2_01681CA7 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0168BF80 | 3_2_0168BF80 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0645F708 | 3_2_0645F708 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0645F9C8 | 3_2_0645F9C8 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0645E610 | 3_2_0645E610 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_06440040 | 3_2_06440040 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_0645E078 | 3_2_0645E078 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 3_2_06440014 | 3_2_06440014 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_00A4C530 | 4_2_00A4C530 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_00A49480 | 4_2_00A49480 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_00A4C521 | 4_2_00A4C521 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_00A4946F | 4_2_00A4946F |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_05FC2630 | 4_2_05FC2630 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_05FC4D78 | 4_2_05FC4D78 |
Source: C:\Users\user\AppData\Roaming\skype.exe | Code function: 4_2_05FCBB91 | 4_2_05FCBB91 |
Source: 1.2.PI 00928292828.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PI 00928292828.exe.44b4218.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PI 00928292828.exe.44b4218.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PI 00928292828.exe.44b4218.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PI 00928292828.exe.44b4218.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000000.00000002.1701269663.00000000044B3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1701269663.00000000042D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000003.00000002.1859555653.00000000045C3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: PI 00928292828.exe PID: 7340, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: skype.exe PID: 7600, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -21213755684765971s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7560 | Thread sleep count: 2263 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7560 | Thread sleep count: 4783 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99746s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99418s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99310s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99168s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -99055s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -98766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -98328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -98203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -98094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97979s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97754s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97625s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97516s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97171s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -97062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96948s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96842s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96625s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96515s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96406s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96293s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96186s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -96078s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95849s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -95000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe TID: 7548 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -17524406870024063s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99884s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8048 | Thread sleep count: 1402 > 30 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8048 | Thread sleep count: 5871 > 30 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99774s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99665s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99556s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99446s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99337s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99227s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99117s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -99009s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98899s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98790s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98681s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98569s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98462s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98352s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98243s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98134s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -98024s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97909s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97790s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97681s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97571s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97462s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97352s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97243s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97134s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -97024s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96898s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96790s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96681s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96571s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96462s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96352s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96243s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -96131s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe TID: 8044 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99859 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99746 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99563 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99418 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99310 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99168 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 99055 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 98766 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 98328 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 98203 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 98094 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97979 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97875 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97754 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97625 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97516 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97391 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97281 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97171 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 97062 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96948 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96842 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96734 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96625 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96515 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96406 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96293 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96186 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 96078 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95968 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95849 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95719 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95453 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95328 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95218 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95109 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 95000 | Jump to behavior |
Source: C:\Users\user\Desktop\PI 00928292828.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99884 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99774 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99665 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99556 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99446 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99337 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99227 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99117 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 99009 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98899 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98790 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98681 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98569 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98462 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98352 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98243 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98134 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 98024 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97909 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97790 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97681 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97571 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97462 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97352 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97243 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97134 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 97024 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96898 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96790 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96681 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96571 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96462 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96352 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96243 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 96131 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\skype.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |