Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://varders.kozow.com:8081 |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org?q= |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:530978%0D%0ADate%20a |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000004058000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000004058000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002ED1000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002F03000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002EC2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002EC2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en0 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002ED1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en4 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002ECC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enlB |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000004058000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtabv20 |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://gemini.google.com/app?q= |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D8F000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002DFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: UFOiZapHGS.exe, 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002D8F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002DFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002DB9000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002E26000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002DFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$ |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000004058000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/v20 |
Source: UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000004058000.00000004.00000800.00020000.00000000.sdmp, UFOiZapHGS.exe, 00000001.00000002.3359990842.0000000003E02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002F03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/ |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002EF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/0 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002F03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/4 |
Source: UFOiZapHGS.exe, 00000001.00000002.3357879942.0000000002EFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/lB |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05980CA0 | 0_2_05980CA0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05985538 | 0_2_05985538 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05980C90 | 0_2_05980C90 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05983CF8 | 0_2_05983CF8 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05982E08 | 0_2_05982E08 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05984130 | 0_2_05984130 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05985970 | 0_2_05985970 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_05985960 | 0_2_05985960 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_059868D0 | 0_2_059868D0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_059868C0 | 0_2_059868C0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727AF58 | 0_2_0727AF58 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07274FC0 | 0_2_07274FC0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07275EE0 | 0_2_07275EE0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07273DB0 | 0_2_07273DB0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07278718 | 0_2_07278718 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727AF47 | 0_2_0727AF47 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07275E7D | 0_2_07275E7D |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B689 | 0_2_0727B689 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B698 | 0_2_0727B698 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07273D19 | 0_2_07273D19 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07276D70 | 0_2_07276D70 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727CDAF | 0_2_0727CDAF |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07276DA8 | 0_2_07276DA8 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727CDB0 | 0_2_0727CDB0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07276DB8 | 0_2_07276DB8 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07275DFD | 0_2_07275DFD |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_072745C0 | 0_2_072745C0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07278428 | 0_2_07278428 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B43F | 0_2_0727B43F |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727841B | 0_2_0727841B |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B440 | 0_2_0727B440 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727C4D1 | 0_2_0727C4D1 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07277BF8 | 0_2_07277BF8 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_072732C1 | 0_2_072732C1 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727818B | 0_2_0727818B |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07278198 | 0_2_07278198 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727C1E0 | 0_2_0727C1E0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B1EF | 0_2_0727B1EF |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727B1F0 | 0_2_0727B1F0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727C1F0 | 0_2_0727C1F0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_07278028 | 0_2_07278028 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727801B | 0_2_0727801B |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727C8CB | 0_2_0727C8CB |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 0_2_0727C8D0 | 0_2_0727C8D0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_01297118 | 1_2_01297118 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129C147 | 1_2_0129C147 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129A088 | 1_2_0129A088 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_01295370 | 1_2_01295370 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129D278 | 1_2_0129D278 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129C468 | 1_2_0129C468 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129C738 | 1_2_0129C738 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_012969A0 | 1_2_012969A0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129E988 | 1_2_0129E988 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129CA08 | 1_2_0129CA08 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129CCD8 | 1_2_0129CCD8 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129CFAA | 1_2_0129CFAA |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129F961 | 1_2_0129F961 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_0129E97A | 1_2_0129E97A |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_012929EC | 1_2_012929EC |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_012939F0 | 1_2_012939F0 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_01293AA1 | 1_2_01293AA1 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Code function: 1_2_01293E09 | 1_2_01293E09 |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 1.2.UFOiZapHGS.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 1.2.UFOiZapHGS.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 1.2.UFOiZapHGS.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.UFOiZapHGS.exe.4305e48.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000001.00000002.3355826178.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.910063870.0000000003FC2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: UFOiZapHGS.exe PID: 6596, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: UFOiZapHGS.exe PID: 6812, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, z1kK0NZZgC0XJYbnPZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wSfU0qnPU3', 'a2LUBufKZ5', 'GZgUzdnWQX', 'lB5qH1hQed', 'RSuqAqwrGI', 'hxHqUJm9fW', 'tWGqq5vNFG', 'wLsMBHI2DY8iqSi3Buk' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, UtVPfr1lW3qEpb6TPt.cs | High entropy of concatenated method names: 'Mxg3dTGPfS', 'vSZ3RmJuOL', 'abTZaT5Z0V', 'cUSZFmWnmM', 'dkhZ7gQv3v', 'YYWZsFtv4L', 'g4bZPwtCKb', 'mrLZ8HZ2Mr', 'lyhZYA6rK9', 'oKTZWAcqw5' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, fLgG2NjKayBElw7pF6.cs | High entropy of concatenated method names: 'RlrZXGgiMF', 'mThZCUl661', 'uOxZ6NHIu7', 'lTTZj5IPvr', 'qQuZpwacEf', 'lJZZMgW2yf', 'qRsZIthEDI', 'OH4ZynHUJC', 'C5kZxQnj6I', 'Yi5ZEgi6B9' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, crEQIxYD98kSnOTwPV.cs | High entropy of concatenated method names: 'TO2twh0JGE', 'T6Ctca075y', 'cTgtoxsrYx', 'DH5tXVBQAT', 'UmJtdppDIJ', 'ILotCTGAQr', 'moxtRe3Z64', 'iCnt6hgUp5', 'QaotjSbI6b', 'c0ht1ydm1r' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, F53hZuviP6sCr447Mm.cs | High entropy of concatenated method names: 'KEvriw4YLk', 'xworGQWiJZ', 'T2Vr3YJsFR', 'kQ5rtOwQt9', 'uEJrkqeUoK', 'vs33VBKa0i', 'GDj3K8j11S', 'N7p3DZt0k6', 'A6Q3OidgCv', 'RhE30C0kaO' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, YRPcnen60xXs813G8l.cs | High entropy of concatenated method names: 'rXUQ6nXKG5', 'o3bQjI0K0s', 'EgWQvGRelX', 'tCDQ2nIL1E', 'f9vQFOSrZR', 'v78Q7X7vC7', 'V1EQPA0gKT', 'Un6Q8ncQPO', 'nPoQWltmyo', 'HjLQ5tQ38R' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, c3OKGSsH3otOS2iZPy.cs | High entropy of concatenated method names: 'o6VrNENlJ4', 'Q8YrLgeQJ1', 'U5HrVLtD5f', 'ToString', 'sbErKsfwCB', 'LI9rDoX0G9', 'zTUup72sviCdiyyLt13', 'FUtfm32cbF2lTHWlru6', 'Caugw42roSoAHUGl8RK' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, zooLG2D1NETVSuCcGH.cs | High entropy of concatenated method names: 'NmBxp3Z0XL', 't8DxIpn2mh', 'WyIxxXTt00', 'MO2xub3UL4', 'MoLxlTmpNS', 'VU9xJSnkoA', 'Dispose', 'ahaymnqgb9', 'KCdyGR9Yx0', 'o3UyZ4WhQP' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, ICRvmKAAcQHSY8gbpCE.cs | High entropy of concatenated method names: 'fxDEBNEmfY', 'V8rEzmSQJb', 'z6TuHnmarc', 'AsNuAELGqW', 'HJ8uU3XidO', 'lQjuqmVjNL', 'oUauSHHeJI', 'kxJuixIMhs', 'W4RumGPMLR', 'nlRuGi3uVq' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, EAvKHf0VSryQELm8rN.cs | High entropy of concatenated method names: 'CsKxv3mfhl', 'tSlx2NwHsv', 'FSvxaej5dr', 'IdLxFSTCxY', 'P4Nx7WsrIT', 'o0uxsg2S17', 'jlFxPJQuxO', 'fNYx8lRm21', 'nrLxY8KaQd', 'S17xW7yZdl' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, h0lKaxk7KDkCXCFAkM.cs | High entropy of concatenated method names: 'ASyqiEJqv8', 'jLLqmLRRLq', 'eoqqGH0dfl', 'D5LqZ2asyY', 'OWlq308cG8', 'KtxqrkJG6P', 'ipjqtclgob', 'Gwlqk4ldK5', 'OuIqfyChLB', 'VWcqbKh7qb' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, roFcEIUNPNfMFQtdu2.cs | High entropy of concatenated method names: 'W7koJii1S', 'jBrXD5D3n', 'orICbc1el', 'BUiRYZ8uP', 'x5wjuZfij', 'KpY1Dy5Uu', 'EkCXH3CsfGtlPSEVZq', 'oehIs5ETGHMae6MyIh', 'M8ryy3f92', 'KJfEQHQRx' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, asLAXfB6W5Ixa3Snel.cs | High entropy of concatenated method names: 'Q1LEZWIhqj', 'UQjE3CaSuy', 'PpREr8tbA9', 'fNyEtYGPcm', 'A60ExVr2TN', 'vBbEk4j7JB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, PF5f0TGGGJmOPQqetg.cs | High entropy of concatenated method names: 'Dispose', 'sTVA0SuCcG', 'hLUU2rr41q', 'tvf7ZSMsuy', 'aIsABqeWKS', 'rXGAzjjd4i', 'ProcessDialogKey', 'S0jUHAvKHf', 'USrUAyQELm', 'LrNUUHsLAX' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, JDtUwoKuo75hSEnrug.cs | High entropy of concatenated method names: 'zieIOyTmVX', 'neNIBHvGtA', 'WT4yHXOisT', 'LOZyAkW50S', 'i0HI5S6tL7', 'evMI94QQVq', 'J8mInvUgUe', 'g3bIeMLaCt', 'gNYIg3QxNS', 'L3nINk91aF' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, noelrBAUQk7dBQSl2gY.cs | High entropy of concatenated method names: 'ToString', 'yMku6Yx4sf', 'Fn0ujM30Ao', 'rp4u1xikvR', 'ovNuvm8hDI', 'W1Gu2g8Zoj', 'iiOuafafRl', 'F5luFaDyQI', 'i45n7CbQqXd0JUVyU4x', 'Jrl2H9bMeEs8tNgWaHe' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, oumZYrSQJH8HN76im8.cs | High entropy of concatenated method names: 'fcuAtTG5u6', 'mvjAke53TX', 'SKaAbyBElw', 'JpFA46VtVP', 'm6TApPt153', 'wZuAMiP6sC', 'KVsaFdZLLG2DyGvymS', 'T2EfIf56drpwg4ZcKh', 'PP9AAQqBfB', 'fwSAq7cR1V' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, qPh7KmAHne0atqquLNL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dR9E5BphVr', 'w5eE9092oh', 'K4iEntiWp5', 'rJUEeD9wbJ', 'Kr6Eget2dA', 'lqOENqoXhD', 'VdIEL8V7LJ' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, rYESTdeEVhin7mQVke.cs | High entropy of concatenated method names: 'WGWpWruvCG', 'Gmmp9WLpPI', 'nB7peYu14W', 'wEypgJcaLU', 'Dd1p2iJkmL', 'osApaxsqEe', 'OWupFHJZq4', 'MwRp7SQ2dH', 'Q8HpsCWIwJ', 'rRhpPOgTi1' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, YsRmyuNdGdZhXTNigh.cs | High entropy of concatenated method names: 'ToString', 'f17M5g9frc', 'wkTM2cajBi', 'CgjMayeyr2', 'IDYMFBUNJf', 'kKVM7TuWNI', 'kajMsDQhtu', 'qB4MPoPFYd', 'y7wM8Eq2Dj', 'tWKMYd4Xf6' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, V8xnZkzbloQN1oqh1t.cs | High entropy of concatenated method names: 'l64ECM7i5f', 'vMgE6Qs4K9', 'NfREjsLPDb', 'CoOEvpk32s', 'fw6E2QrwDK', 'Kv7EFbAETD', 'CghE7r57bQ', 'JOfEJKBimh', 'ynoEw922Df', 'H1fEcKBFLt' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, NfMc5VP5elSuT97t75.cs | High entropy of concatenated method names: 'ywgtm0kyQ7', 'J0gtZLJmEl', 'wB0trIwCvH', 'Hv3rB5sHPi', 'zERrzH82EX', 'PH5tHjs5e4', 'qlCtABQigZ', 'jNttUNyCBd', 'DartqGM4CJ', 'rVGtSpR4FS' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, tTG5u66bvje53TXubH.cs | High entropy of concatenated method names: 'p2wGevn2IC', 'PEyGgFPhUj', 'noYGN2YKnI', 'wRsGLlXtCJ', 'UpTGVbCwn6', 'prAGKP8mxo', 'mpaGDmvV4A', 'HbYGOxLmQK', 'r20G0Hx9nQ', 'rMkGBGTnbC' |
Source: 0.2.UFOiZapHGS.exe.41f6e08.2.raw.unpack, Tb71NqASyY2jsVR0Wv5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'vSvTxKdyTK', 'DkdTEO5dMK', 'e9PTuDUXMK', 'yo3TTY05ak', 'sblTlIw1DY', 'RTUThjZcAc', 'EqZTJUADcD' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, z1kK0NZZgC0XJYbnPZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wSfU0qnPU3', 'a2LUBufKZ5', 'GZgUzdnWQX', 'lB5qH1hQed', 'RSuqAqwrGI', 'hxHqUJm9fW', 'tWGqq5vNFG', 'wLsMBHI2DY8iqSi3Buk' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, UtVPfr1lW3qEpb6TPt.cs | High entropy of concatenated method names: 'Mxg3dTGPfS', 'vSZ3RmJuOL', 'abTZaT5Z0V', 'cUSZFmWnmM', 'dkhZ7gQv3v', 'YYWZsFtv4L', 'g4bZPwtCKb', 'mrLZ8HZ2Mr', 'lyhZYA6rK9', 'oKTZWAcqw5' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, fLgG2NjKayBElw7pF6.cs | High entropy of concatenated method names: 'RlrZXGgiMF', 'mThZCUl661', 'uOxZ6NHIu7', 'lTTZj5IPvr', 'qQuZpwacEf', 'lJZZMgW2yf', 'qRsZIthEDI', 'OH4ZynHUJC', 'C5kZxQnj6I', 'Yi5ZEgi6B9' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, crEQIxYD98kSnOTwPV.cs | High entropy of concatenated method names: 'TO2twh0JGE', 'T6Ctca075y', 'cTgtoxsrYx', 'DH5tXVBQAT', 'UmJtdppDIJ', 'ILotCTGAQr', 'moxtRe3Z64', 'iCnt6hgUp5', 'QaotjSbI6b', 'c0ht1ydm1r' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, F53hZuviP6sCr447Mm.cs | High entropy of concatenated method names: 'KEvriw4YLk', 'xworGQWiJZ', 'T2Vr3YJsFR', 'kQ5rtOwQt9', 'uEJrkqeUoK', 'vs33VBKa0i', 'GDj3K8j11S', 'N7p3DZt0k6', 'A6Q3OidgCv', 'RhE30C0kaO' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, YRPcnen60xXs813G8l.cs | High entropy of concatenated method names: 'rXUQ6nXKG5', 'o3bQjI0K0s', 'EgWQvGRelX', 'tCDQ2nIL1E', 'f9vQFOSrZR', 'v78Q7X7vC7', 'V1EQPA0gKT', 'Un6Q8ncQPO', 'nPoQWltmyo', 'HjLQ5tQ38R' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, c3OKGSsH3otOS2iZPy.cs | High entropy of concatenated method names: 'o6VrNENlJ4', 'Q8YrLgeQJ1', 'U5HrVLtD5f', 'ToString', 'sbErKsfwCB', 'LI9rDoX0G9', 'zTUup72sviCdiyyLt13', 'FUtfm32cbF2lTHWlru6', 'Caugw42roSoAHUGl8RK' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, zooLG2D1NETVSuCcGH.cs | High entropy of concatenated method names: 'NmBxp3Z0XL', 't8DxIpn2mh', 'WyIxxXTt00', 'MO2xub3UL4', 'MoLxlTmpNS', 'VU9xJSnkoA', 'Dispose', 'ahaymnqgb9', 'KCdyGR9Yx0', 'o3UyZ4WhQP' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, ICRvmKAAcQHSY8gbpCE.cs | High entropy of concatenated method names: 'fxDEBNEmfY', 'V8rEzmSQJb', 'z6TuHnmarc', 'AsNuAELGqW', 'HJ8uU3XidO', 'lQjuqmVjNL', 'oUauSHHeJI', 'kxJuixIMhs', 'W4RumGPMLR', 'nlRuGi3uVq' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, EAvKHf0VSryQELm8rN.cs | High entropy of concatenated method names: 'CsKxv3mfhl', 'tSlx2NwHsv', 'FSvxaej5dr', 'IdLxFSTCxY', 'P4Nx7WsrIT', 'o0uxsg2S17', 'jlFxPJQuxO', 'fNYx8lRm21', 'nrLxY8KaQd', 'S17xW7yZdl' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, h0lKaxk7KDkCXCFAkM.cs | High entropy of concatenated method names: 'ASyqiEJqv8', 'jLLqmLRRLq', 'eoqqGH0dfl', 'D5LqZ2asyY', 'OWlq308cG8', 'KtxqrkJG6P', 'ipjqtclgob', 'Gwlqk4ldK5', 'OuIqfyChLB', 'VWcqbKh7qb' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, roFcEIUNPNfMFQtdu2.cs | High entropy of concatenated method names: 'W7koJii1S', 'jBrXD5D3n', 'orICbc1el', 'BUiRYZ8uP', 'x5wjuZfij', 'KpY1Dy5Uu', 'EkCXH3CsfGtlPSEVZq', 'oehIs5ETGHMae6MyIh', 'M8ryy3f92', 'KJfEQHQRx' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, asLAXfB6W5Ixa3Snel.cs | High entropy of concatenated method names: 'Q1LEZWIhqj', 'UQjE3CaSuy', 'PpREr8tbA9', 'fNyEtYGPcm', 'A60ExVr2TN', 'vBbEk4j7JB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, PF5f0TGGGJmOPQqetg.cs | High entropy of concatenated method names: 'Dispose', 'sTVA0SuCcG', 'hLUU2rr41q', 'tvf7ZSMsuy', 'aIsABqeWKS', 'rXGAzjjd4i', 'ProcessDialogKey', 'S0jUHAvKHf', 'USrUAyQELm', 'LrNUUHsLAX' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, JDtUwoKuo75hSEnrug.cs | High entropy of concatenated method names: 'zieIOyTmVX', 'neNIBHvGtA', 'WT4yHXOisT', 'LOZyAkW50S', 'i0HI5S6tL7', 'evMI94QQVq', 'J8mInvUgUe', 'g3bIeMLaCt', 'gNYIg3QxNS', 'L3nINk91aF' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, noelrBAUQk7dBQSl2gY.cs | High entropy of concatenated method names: 'ToString', 'yMku6Yx4sf', 'Fn0ujM30Ao', 'rp4u1xikvR', 'ovNuvm8hDI', 'W1Gu2g8Zoj', 'iiOuafafRl', 'F5luFaDyQI', 'i45n7CbQqXd0JUVyU4x', 'Jrl2H9bMeEs8tNgWaHe' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, oumZYrSQJH8HN76im8.cs | High entropy of concatenated method names: 'fcuAtTG5u6', 'mvjAke53TX', 'SKaAbyBElw', 'JpFA46VtVP', 'm6TApPt153', 'wZuAMiP6sC', 'KVsaFdZLLG2DyGvymS', 'T2EfIf56drpwg4ZcKh', 'PP9AAQqBfB', 'fwSAq7cR1V' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, qPh7KmAHne0atqquLNL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dR9E5BphVr', 'w5eE9092oh', 'K4iEntiWp5', 'rJUEeD9wbJ', 'Kr6Eget2dA', 'lqOENqoXhD', 'VdIEL8V7LJ' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, rYESTdeEVhin7mQVke.cs | High entropy of concatenated method names: 'WGWpWruvCG', 'Gmmp9WLpPI', 'nB7peYu14W', 'wEypgJcaLU', 'Dd1p2iJkmL', 'osApaxsqEe', 'OWupFHJZq4', 'MwRp7SQ2dH', 'Q8HpsCWIwJ', 'rRhpPOgTi1' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, YsRmyuNdGdZhXTNigh.cs | High entropy of concatenated method names: 'ToString', 'f17M5g9frc', 'wkTM2cajBi', 'CgjMayeyr2', 'IDYMFBUNJf', 'kKVM7TuWNI', 'kajMsDQhtu', 'qB4MPoPFYd', 'y7wM8Eq2Dj', 'tWKMYd4Xf6' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, V8xnZkzbloQN1oqh1t.cs | High entropy of concatenated method names: 'l64ECM7i5f', 'vMgE6Qs4K9', 'NfREjsLPDb', 'CoOEvpk32s', 'fw6E2QrwDK', 'Kv7EFbAETD', 'CghE7r57bQ', 'JOfEJKBimh', 'ynoEw922Df', 'H1fEcKBFLt' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, NfMc5VP5elSuT97t75.cs | High entropy of concatenated method names: 'ywgtm0kyQ7', 'J0gtZLJmEl', 'wB0trIwCvH', 'Hv3rB5sHPi', 'zERrzH82EX', 'PH5tHjs5e4', 'qlCtABQigZ', 'jNttUNyCBd', 'DartqGM4CJ', 'rVGtSpR4FS' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, tTG5u66bvje53TXubH.cs | High entropy of concatenated method names: 'p2wGevn2IC', 'PEyGgFPhUj', 'noYGN2YKnI', 'wRsGLlXtCJ', 'UpTGVbCwn6', 'prAGKP8mxo', 'mpaGDmvV4A', 'HbYGOxLmQK', 'r20G0Hx9nQ', 'rMkGBGTnbC' |
Source: 0.2.UFOiZapHGS.exe.427e628.3.raw.unpack, Tb71NqASyY2jsVR0Wv5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'vSvTxKdyTK', 'DkdTEO5dMK', 'e9PTuDUXMK', 'yo3TTY05ak', 'sblTlIw1DY', 'RTUThjZcAc', 'EqZTJUADcD' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, z1kK0NZZgC0XJYbnPZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wSfU0qnPU3', 'a2LUBufKZ5', 'GZgUzdnWQX', 'lB5qH1hQed', 'RSuqAqwrGI', 'hxHqUJm9fW', 'tWGqq5vNFG', 'wLsMBHI2DY8iqSi3Buk' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, UtVPfr1lW3qEpb6TPt.cs | High entropy of concatenated method names: 'Mxg3dTGPfS', 'vSZ3RmJuOL', 'abTZaT5Z0V', 'cUSZFmWnmM', 'dkhZ7gQv3v', 'YYWZsFtv4L', 'g4bZPwtCKb', 'mrLZ8HZ2Mr', 'lyhZYA6rK9', 'oKTZWAcqw5' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, fLgG2NjKayBElw7pF6.cs | High entropy of concatenated method names: 'RlrZXGgiMF', 'mThZCUl661', 'uOxZ6NHIu7', 'lTTZj5IPvr', 'qQuZpwacEf', 'lJZZMgW2yf', 'qRsZIthEDI', 'OH4ZynHUJC', 'C5kZxQnj6I', 'Yi5ZEgi6B9' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, crEQIxYD98kSnOTwPV.cs | High entropy of concatenated method names: 'TO2twh0JGE', 'T6Ctca075y', 'cTgtoxsrYx', 'DH5tXVBQAT', 'UmJtdppDIJ', 'ILotCTGAQr', 'moxtRe3Z64', 'iCnt6hgUp5', 'QaotjSbI6b', 'c0ht1ydm1r' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, F53hZuviP6sCr447Mm.cs | High entropy of concatenated method names: 'KEvriw4YLk', 'xworGQWiJZ', 'T2Vr3YJsFR', 'kQ5rtOwQt9', 'uEJrkqeUoK', 'vs33VBKa0i', 'GDj3K8j11S', 'N7p3DZt0k6', 'A6Q3OidgCv', 'RhE30C0kaO' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, YRPcnen60xXs813G8l.cs | High entropy of concatenated method names: 'rXUQ6nXKG5', 'o3bQjI0K0s', 'EgWQvGRelX', 'tCDQ2nIL1E', 'f9vQFOSrZR', 'v78Q7X7vC7', 'V1EQPA0gKT', 'Un6Q8ncQPO', 'nPoQWltmyo', 'HjLQ5tQ38R' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, c3OKGSsH3otOS2iZPy.cs | High entropy of concatenated method names: 'o6VrNENlJ4', 'Q8YrLgeQJ1', 'U5HrVLtD5f', 'ToString', 'sbErKsfwCB', 'LI9rDoX0G9', 'zTUup72sviCdiyyLt13', 'FUtfm32cbF2lTHWlru6', 'Caugw42roSoAHUGl8RK' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, zooLG2D1NETVSuCcGH.cs | High entropy of concatenated method names: 'NmBxp3Z0XL', 't8DxIpn2mh', 'WyIxxXTt00', 'MO2xub3UL4', 'MoLxlTmpNS', 'VU9xJSnkoA', 'Dispose', 'ahaymnqgb9', 'KCdyGR9Yx0', 'o3UyZ4WhQP' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, ICRvmKAAcQHSY8gbpCE.cs | High entropy of concatenated method names: 'fxDEBNEmfY', 'V8rEzmSQJb', 'z6TuHnmarc', 'AsNuAELGqW', 'HJ8uU3XidO', 'lQjuqmVjNL', 'oUauSHHeJI', 'kxJuixIMhs', 'W4RumGPMLR', 'nlRuGi3uVq' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, EAvKHf0VSryQELm8rN.cs | High entropy of concatenated method names: 'CsKxv3mfhl', 'tSlx2NwHsv', 'FSvxaej5dr', 'IdLxFSTCxY', 'P4Nx7WsrIT', 'o0uxsg2S17', 'jlFxPJQuxO', 'fNYx8lRm21', 'nrLxY8KaQd', 'S17xW7yZdl' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, h0lKaxk7KDkCXCFAkM.cs | High entropy of concatenated method names: 'ASyqiEJqv8', 'jLLqmLRRLq', 'eoqqGH0dfl', 'D5LqZ2asyY', 'OWlq308cG8', 'KtxqrkJG6P', 'ipjqtclgob', 'Gwlqk4ldK5', 'OuIqfyChLB', 'VWcqbKh7qb' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, roFcEIUNPNfMFQtdu2.cs | High entropy of concatenated method names: 'W7koJii1S', 'jBrXD5D3n', 'orICbc1el', 'BUiRYZ8uP', 'x5wjuZfij', 'KpY1Dy5Uu', 'EkCXH3CsfGtlPSEVZq', 'oehIs5ETGHMae6MyIh', 'M8ryy3f92', 'KJfEQHQRx' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, asLAXfB6W5Ixa3Snel.cs | High entropy of concatenated method names: 'Q1LEZWIhqj', 'UQjE3CaSuy', 'PpREr8tbA9', 'fNyEtYGPcm', 'A60ExVr2TN', 'vBbEk4j7JB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, PF5f0TGGGJmOPQqetg.cs | High entropy of concatenated method names: 'Dispose', 'sTVA0SuCcG', 'hLUU2rr41q', 'tvf7ZSMsuy', 'aIsABqeWKS', 'rXGAzjjd4i', 'ProcessDialogKey', 'S0jUHAvKHf', 'USrUAyQELm', 'LrNUUHsLAX' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, JDtUwoKuo75hSEnrug.cs | High entropy of concatenated method names: 'zieIOyTmVX', 'neNIBHvGtA', 'WT4yHXOisT', 'LOZyAkW50S', 'i0HI5S6tL7', 'evMI94QQVq', 'J8mInvUgUe', 'g3bIeMLaCt', 'gNYIg3QxNS', 'L3nINk91aF' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, noelrBAUQk7dBQSl2gY.cs | High entropy of concatenated method names: 'ToString', 'yMku6Yx4sf', 'Fn0ujM30Ao', 'rp4u1xikvR', 'ovNuvm8hDI', 'W1Gu2g8Zoj', 'iiOuafafRl', 'F5luFaDyQI', 'i45n7CbQqXd0JUVyU4x', 'Jrl2H9bMeEs8tNgWaHe' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, oumZYrSQJH8HN76im8.cs | High entropy of concatenated method names: 'fcuAtTG5u6', 'mvjAke53TX', 'SKaAbyBElw', 'JpFA46VtVP', 'm6TApPt153', 'wZuAMiP6sC', 'KVsaFdZLLG2DyGvymS', 'T2EfIf56drpwg4ZcKh', 'PP9AAQqBfB', 'fwSAq7cR1V' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, qPh7KmAHne0atqquLNL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dR9E5BphVr', 'w5eE9092oh', 'K4iEntiWp5', 'rJUEeD9wbJ', 'Kr6Eget2dA', 'lqOENqoXhD', 'VdIEL8V7LJ' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, rYESTdeEVhin7mQVke.cs | High entropy of concatenated method names: 'WGWpWruvCG', 'Gmmp9WLpPI', 'nB7peYu14W', 'wEypgJcaLU', 'Dd1p2iJkmL', 'osApaxsqEe', 'OWupFHJZq4', 'MwRp7SQ2dH', 'Q8HpsCWIwJ', 'rRhpPOgTi1' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, YsRmyuNdGdZhXTNigh.cs | High entropy of concatenated method names: 'ToString', 'f17M5g9frc', 'wkTM2cajBi', 'CgjMayeyr2', 'IDYMFBUNJf', 'kKVM7TuWNI', 'kajMsDQhtu', 'qB4MPoPFYd', 'y7wM8Eq2Dj', 'tWKMYd4Xf6' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, V8xnZkzbloQN1oqh1t.cs | High entropy of concatenated method names: 'l64ECM7i5f', 'vMgE6Qs4K9', 'NfREjsLPDb', 'CoOEvpk32s', 'fw6E2QrwDK', 'Kv7EFbAETD', 'CghE7r57bQ', 'JOfEJKBimh', 'ynoEw922Df', 'H1fEcKBFLt' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, NfMc5VP5elSuT97t75.cs | High entropy of concatenated method names: 'ywgtm0kyQ7', 'J0gtZLJmEl', 'wB0trIwCvH', 'Hv3rB5sHPi', 'zERrzH82EX', 'PH5tHjs5e4', 'qlCtABQigZ', 'jNttUNyCBd', 'DartqGM4CJ', 'rVGtSpR4FS' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, tTG5u66bvje53TXubH.cs | High entropy of concatenated method names: 'p2wGevn2IC', 'PEyGgFPhUj', 'noYGN2YKnI', 'wRsGLlXtCJ', 'UpTGVbCwn6', 'prAGKP8mxo', 'mpaGDmvV4A', 'HbYGOxLmQK', 'r20G0Hx9nQ', 'rMkGBGTnbC' |
Source: 0.2.UFOiZapHGS.exe.af70000.6.raw.unpack, Tb71NqASyY2jsVR0Wv5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'vSvTxKdyTK', 'DkdTEO5dMK', 'e9PTuDUXMK', 'yo3TTY05ak', 'sblTlIw1DY', 'RTUThjZcAc', 'EqZTJUADcD' |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599641 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598865 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598750 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598640 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598312 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598203 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597874 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597546 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597098 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596983 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596872 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596757 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596643 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596516 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596405 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596297 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596187 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596078 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595969 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595859 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595750 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595313 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595188 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595063 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594718 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594609 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594500 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 6640 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep count: 37 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -34126476536362649s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7016 | Thread sleep count: 1869 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7016 | Thread sleep count: 7983 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -599094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598865s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -598094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -597098s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596983s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596872s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596757s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596643s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596516s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596405s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596297s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596187s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -596078s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595969s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -595063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -594938s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -594828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -594718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -594609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe TID: 7024 | Thread sleep time: -594500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599641 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598865 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598750 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598640 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598312 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598203 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597874 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597546 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 597098 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596983 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596872 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596757 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596643 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596516 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596405 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596297 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596187 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 596078 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595969 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595859 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595750 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595531 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595422 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595313 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595188 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 595063 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594718 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594609 | Jump to behavior |
Source: C:\Users\user\Desktop\UFOiZapHGS.exe | Thread delayed: delay time: 594500 | Jump to behavior |