Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
0_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_00405E9C FindFirstFileA,FindClose, |
0_2_00405E9C |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_0040264F FindFirstFileA, |
0_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_0040264F FindFirstFileA, |
12_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
12_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_00405E9C FindFirstFileA,FindClose, |
12_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
13_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_00405E9C FindFirstFileA,FindClose, |
13_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_0040264F FindFirstFileA, |
13_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
15_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_00405E9C FindFirstFileA,FindClose, |
15_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_0040264F FindFirstFileA, |
15_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
16_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_00405E9C FindFirstFileA,FindClose, |
16_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_0040264F FindFirstFileA, |
16_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
17_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_00405E9C FindFirstFileA,FindClose, |
17_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_0040264F FindFirstFileA, |
17_2_0040264F |
Source: remcos.exe, remcos.exe, 00000011.00000000.2380438690.0000000000409000.00000008.00000001.01000000.0000000A.sdmp, remcos.exe, 00000011.00000002.2503857103.0000000000409000.00000004.00000001.01000000.0000000A.sdmp, Payment slip_pdf.pif.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: Payment slip_pdf.pif.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005625000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2165121027.0000000034C90000.00000004.00001000.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005641000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1tGFKOOy5IKzQd8rTIWKS81wv12OARueJ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005671000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005641000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1tGFKOOy5IKzQd8rTIWKS81wv12OARueJ&export=download |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_0040310B |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
12_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
13_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
15_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
16_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
17_2_0040310B |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
0_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_00405E9C FindFirstFileA,FindClose, |
0_2_00405E9C |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 0_2_0040264F FindFirstFileA, |
0_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_0040264F FindFirstFileA, |
12_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
12_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe |
Code function: 12_2_00405E9C FindFirstFileA,FindClose, |
12_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
13_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_00405E9C FindFirstFileA,FindClose, |
13_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 13_2_0040264F FindFirstFileA, |
13_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
15_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_00405E9C FindFirstFileA,FindClose, |
15_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 15_2_0040264F FindFirstFileA, |
15_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
16_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_00405E9C FindFirstFileA,FindClose, |
16_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 16_2_0040264F FindFirstFileA, |
16_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, |
17_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_00405E9C FindFirstFileA,FindClose, |
17_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe |
Code function: 17_2_0040264F FindFirstFileA, |
17_2_0040264F |