Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0059445A |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059C6D1 FindFirstFileW,FindClose, | 0_2_0059C6D1 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0059C75C |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0059EF95 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0059F0F2 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0059F3F3 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005937EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_005937EF |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00593B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00593B12 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0059BCBC |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C445A GetFileAttributesW,FindFirstFileW,FindClose, | 1_2_003C445A |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CC6D1 FindFirstFileW,FindClose, | 1_2_003CC6D1 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 1_2_003CC75C |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003CEF95 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003CF0F2 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003CF3F3 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003C37EF |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003C3B12 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003CBCBC |
Source: RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.gl |
Source: RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000032C3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gsrsaovsslca2018.crl0j |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000072F6000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057C4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057C4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/root.crl0G |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.glo |
Source: RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000032C3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.globalsign.com/gsrsaovsslca20180V |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057C4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.globalsign.com/rootr103 |
Source: RegSvcs.exe, 0000000B.00000002.3698327112.00000000072F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.globalsign.com/rootr1E |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000072F6000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057C4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: RegSvcs.exe, 00000002.00000002.1388940920.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000031C0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000032C3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gsrsaovsslca2018.crt07 |
Source: RegSvcs.exe, 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388122756.000000000263E000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1390461654.00000000039D1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: RegSvcs.exe, 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388122756.000000000263E000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1390461654.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000031C0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org |
Source: RegSvcs.exe, 00000002.00000002.1388940920.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000031C0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/ |
Source: RegSvcs.exe, 00000002.00000002.1388940920.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000031C0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/t |
Source: RegSvcs.exe, 00000002.00000002.1391441598.00000000050B4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.1387048610.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000338D000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057E2000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000034F0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003589000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.0000000003322000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3684345073.00000000013EA000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000072F6000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698203872.00000000071C5000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000032C3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3695278683.00000000057C4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3698327112.00000000071E4000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.00000000033D0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 0000000B.00000002.3687027989.000000000362A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005BCABC DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_005BCABC |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003ECABC DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 1_2_003ECABC |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.39d6458.4.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.4eb0ee8.7.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.267fd8e.1.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.267eea6.2.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.39d5570.5.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.39d5570.5.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 10.2.vehiculate.exe.3f20000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 2.2.RegSvcs.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.4eb0000.6.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.3a22d90.3.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.4eb0000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 1.2.vehiculate.exe.1f80000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.267eea6.2.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 2.2.RegSvcs.exe.5180000.8.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0000000A.00000002.1382722442.0000000003F20000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 00000001.00000002.1244596938.0000000001F80000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: 00000002.00000002.1385874503.0000000000400000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Detects RedLine infostealer Author: ditekSHen |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: This is a third-party compiled AutoIt script. | 0_2_00533B3A |
Source: Wi8JY2Ta81.exe | String found in binary or memory: This is a third-party compiled AutoIt script. | |
Source: Wi8JY2Ta81.exe, 00000000.00000002.1222446482.00000000005E4000.00000002.00000001.01000000.00000003.sdmp | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_9558f54f-4 |
Source: Wi8JY2Ta81.exe, 00000000.00000002.1222446482.00000000005E4000.00000002.00000001.01000000.00000003.sdmp | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_af16c4e6-b |
Source: Wi8JY2Ta81.exe, 00000000.00000003.1221043775.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_92c7f992-e |
Source: Wi8JY2Ta81.exe, 00000000.00000003.1221043775.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_20aa2195-8 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: This is a third-party compiled AutoIt script. | 1_2_00363B3A |
Source: vehiculate.exe | String found in binary or memory: This is a third-party compiled AutoIt script. | |
Source: vehiculate.exe, 00000001.00000002.1243690262.0000000000414000.00000002.00000001.01000000.00000004.sdmp | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_729266dc-0 |
Source: vehiculate.exe, 00000001.00000002.1243690262.0000000000414000.00000002.00000001.01000000.00000004.sdmp | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_cbf4498f-1 |
Source: vehiculate.exe, 0000000A.00000002.1381970110.0000000000414000.00000002.00000001.01000000.00000004.sdmp | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_1d5bbd3e-d |
Source: vehiculate.exe, 0000000A.00000002.1381970110.0000000000414000.00000002.00000001.01000000.00000004.sdmp | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_37b1a011-4 |
Source: Wi8JY2Ta81.exe | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_9fa01537-c |
Source: Wi8JY2Ta81.exe | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_bd383fb3-2 |
Source: vehiculate.exe.0.dr | String found in binary or memory: This is a third-party compiled AutoIt script. | memstr_34811a9a-e |
Source: vehiculate.exe.0.dr | String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer` | memstr_7d7dc3a3-2 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0055D975 | 0_2_0055D975 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005521C5 | 0_2_005521C5 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005662D2 | 0_2_005662D2 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005B03DA | 0_2_005B03DA |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0056242E | 0_2_0056242E |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005525FA | 0_2_005525FA |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0058E616 | 0_2_0058E616 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005466E1 | 0_2_005466E1 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0053E6A0 | 0_2_0053E6A0 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0056878F | 0_2_0056878F |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005B0857 | 0_2_005B0857 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00566844 | 0_2_00566844 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00548808 | 0_2_00548808 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00598889 | 0_2_00598889 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0055CB21 | 0_2_0055CB21 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00566DB6 | 0_2_00566DB6 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00546F9E | 0_2_00546F9E |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00543030 | 0_2_00543030 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0055F1D9 | 0_2_0055F1D9 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00553187 | 0_2_00553187 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00531287 | 0_2_00531287 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00551484 | 0_2_00551484 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00545520 | 0_2_00545520 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00557696 | 0_2_00557696 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00545760 | 0_2_00545760 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00551978 | 0_2_00551978 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00569AB5 | 0_2_00569AB5 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0053FCE0 | 0_2_0053FCE0 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005B7DDB | 0_2_005B7DDB |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00551D90 | 0_2_00551D90 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0055BDA6 | 0_2_0055BDA6 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0053DF00 | 0_2_0053DF00 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00543FE0 | 0_2_00543FE0 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_014D36C0 | 0_2_014D36C0 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0038D975 | 1_2_0038D975 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003821C5 | 1_2_003821C5 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003962D2 | 1_2_003962D2 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003E03DA | 1_2_003E03DA |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0039242E | 1_2_0039242E |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003825FA | 1_2_003825FA |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003BE616 | 1_2_003BE616 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0036E6A0 | 1_2_0036E6A0 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003766E1 | 1_2_003766E1 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0039878F | 1_2_0039878F |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00378808 | 1_2_00378808 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003E0857 | 1_2_003E0857 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00396844 | 1_2_00396844 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C8889 | 1_2_003C8889 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0038CB21 | 1_2_0038CB21 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00396DB6 | 1_2_00396DB6 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00376F9E | 1_2_00376F9E |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00373030 | 1_2_00373030 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00383187 | 1_2_00383187 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0038F1D9 | 1_2_0038F1D9 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00361287 | 1_2_00361287 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00381484 | 1_2_00381484 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00375520 | 1_2_00375520 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00387696 | 1_2_00387696 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00375760 | 1_2_00375760 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00381978 | 1_2_00381978 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00399AB5 | 1_2_00399AB5 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0036FCE0 | 1_2_0036FCE0 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0038BDA6 | 1_2_0038BDA6 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00381D90 | 1_2_00381D90 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003E7DDB | 1_2_003E7DDB |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0036DF00 | 1_2_0036DF00 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00373FE0 | 1_2_00373FE0 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_01F736C0 | 1_2_01F736C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00408C60 | 2_2_00408C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0040DC11 | 2_2_0040DC11 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00407C3F | 2_2_00407C3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00418CCC | 2_2_00418CCC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00406CA0 | 2_2_00406CA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_004028B0 | 2_2_004028B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0041A4BE | 2_2_0041A4BE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00418244 | 2_2_00418244 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00401650 | 2_2_00401650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00402F20 | 2_2_00402F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_004193C4 | 2_2_004193C4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00418788 | 2_2_00418788 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00402F89 | 2_2_00402F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00402B90 | 2_2_00402B90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_004073A0 | 2_2_004073A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027CD440 | 2_2_027CD440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027CC828 | 2_2_027CC828 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027CCB70 | 2_2_027CCB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027C0FD0 | 2_2_027C0FD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027C1030 | 2_2_027C1030 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056E5F38 | 2_2_056E5F38 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056E61E9 | 2_2_056E61E9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056EC888 | 2_2_056EC888 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056EEB70 | 2_2_056EEB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056E92B0 | 2_2_056E92B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056E0040 | 2_2_056E0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056E0006 | 2_2_056E0006 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_056EF2BB | 2_2_056EF2BB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0643C09C | 2_2_0643C09C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06434E20 | 2_2_06434E20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06435DA8 | 2_2_06435DA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06439DB0 | 2_2_06439DB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0643D6FA | 2_2_0643D6FA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06431138 | 2_2_06431138 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06579FB8 | 2_2_06579FB8 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 10_2_016D36C0 | 10_2_016D36C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FECB80 | 11_2_02FECB80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FED450 | 11_2_02FED450 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FEC838 | 11_2_02FEC838 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FE0FD0 | 11_2_02FE0FD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FE1030 | 11_2_02FE1030 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06785F28 | 11_2_06785F28 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_0678BA78 | 11_2_0678BA78 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06789368 | 11_2_06789368 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_0678EB60 | 11_2_0678EB60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_067861D9 | 11_2_067861D9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_0678F2C0 | 11_2_0678F2C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06780040 | 11_2_06780040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_0678001F | 11_2_0678001F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BAC09C | 11_2_06BAC09C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BA0040 | 11_2_06BA0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BA4E30 | 11_2_06BA4E30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BA9DB0 | 11_2_06BA9DB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BA5DA8 | 11_2_06BA5DA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BAD6FA | 11_2_06BAD6FA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BA1138 | 11_2_06BA1138 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06CE9FB8 | 11_2_06CE9FB8 |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.39d6458.4.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.4eb0ee8.7.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.267fd8e.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.267eea6.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.39d5570.5.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.39d5570.5.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 10.2.vehiculate.exe.3f20000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 2.2.RegSvcs.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.4eb0000.6.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.3a22d90.3.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.4eb0000.6.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.vehiculate.exe.1f80000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.267eea6.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.5180000.8.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0000000A.00000002.1382722442.0000000003F20000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 00000001.00000002.1244596938.0000000001F80000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 00000002.00000002.1385874503.0000000000400000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0053C4C6 push A30053BAh; retn 0053h | 0_2_0053C50D |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00558945 push ecx; ret | 0_2_00558958 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_0036C4FE push A30036BAh; retn 0036h | 1_2_0036C50D |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_00388945 push ecx; ret | 1_2_00388958 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0041C40C push cs; iretd | 2_2_0041C4E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_00423149 push eax; ret | 2_2_00423179 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0041C50E push cs; iretd | 2_2_0041C4E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_004231C8 push eax; ret | 2_2_00423179 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0040E21D push ecx; ret | 2_2_0040E230 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0041C6BE push ebx; ret | 2_2_0041C6BF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027C47AC push es; retf | 2_2_027C47AF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_027C2582 pushfd ; ret | 2_2_027C2597 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0643CF5A push esp; ret | 2_2_0643CF61 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06576290 push es; ret | 2_2_065762A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06571E71 push es; ret | 2_2_06571E80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0657FFB2 pushfd ; ret | 2_2_0657FFB9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0657D9CC push es; ret | 2_2_0657D9AC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0657D9A6 push es; ret | 2_2_0657D9AC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FE47AC push es; retf | 11_2_02FE47AF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_02FE2582 pushfd ; ret | 11_2_02FE2597 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06BACF5A push esp; ret | 11_2_06BACF61 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06CED9CC push es; ret | 11_2_06CED9AC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 11_2_06CED9A6 push es; ret | 11_2_06CED9AC |
Source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, WP6RZJql8gZrNhVA9v.cs | High entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'zmbiqYKUAsJDQ', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB' |
Source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, WP6RZJql8gZrNhVA9v.cs | High entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'zmbiqYKUAsJDQ', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB' |
Source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, WP6RZJql8gZrNhVA9v.cs | High entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'zmbiqYKUAsJDQ', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB' |
Source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, WP6RZJql8gZrNhVA9v.cs | High entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'zmbiqYKUAsJDQ', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB' |
Source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, WP6RZJql8gZrNhVA9v.cs | High entropy of concatenated method names: 'G9skPDgcXb', 'KDikMXewCI', 'B2XkaLi4dH', 'hx5kqNgSj4', 'TVtkAMaqpL', 'VDqkQKyKML', 'zmbiqYKUAsJDQ', 'ab9oDe4UH3', 'TAOohhiP7R', 'zDKosecjaB' |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005348D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 0_2_005348D7 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005B5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 0_2_005B5376 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003648D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 1_2_003648D7 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003E5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 1_2_003E5376 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199653 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199532 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199420 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199078 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198726 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198516 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198263 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199265 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198608 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0059445A |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059C6D1 FindFirstFileW,FindClose, | 0_2_0059C6D1 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0059C75C |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0059EF95 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0059F0F2 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0059F3F3 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_005937EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_005937EF |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_00593B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00593B12 |
Source: C:\Users\user\Desktop\Wi8JY2Ta81.exe | Code function: 0_2_0059BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0059BCBC |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C445A GetFileAttributesW,FindFirstFileW,FindClose, | 1_2_003C445A |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CC6D1 FindFirstFileW,FindClose, | 1_2_003CC6D1 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 1_2_003CC75C |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003CEF95 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003CF0F2 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003CF3F3 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003C37EF |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003C3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003C3B12 |
Source: C:\Users\user\AppData\Local\incalculability\vehiculate.exe | Code function: 1_2_003CBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003CBCBC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99764 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99546 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99405 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99295 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99186 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99044 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98910 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98774 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98436 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98097 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97968 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97749 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97640 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97531 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97413 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97187 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97078 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96968 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96750 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96640 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96531 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96306 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96202 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96073 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 95948 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199653 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199532 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199420 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199078 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198726 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198516 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198263 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 99094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98984 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 98000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 97015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96904 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96794 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96685 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96556 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96404 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96275 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96171 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 96062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 95953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199265 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1199047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198608 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 1198500 | Jump to behavior |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388122756.000000000263E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390461654.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A4F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A24000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7100, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7292, type: MEMORYSTR |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388122756.000000000263E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390461654.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A24000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7100, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7292, type: MEMORYSTR |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267fd8e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d5570.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.39d6458.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.3a22d90.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.4eb0ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.267eea6.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.5180000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000002.00000002.1391884134.0000000005180000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.3687027989.0000000003204000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390795918.0000000004EB0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388122756.000000000263E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1390461654.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A4F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A57000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.1388940920.0000000002A24000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7100, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 7292, type: MEMORYSTR |