Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 0_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_00405E9C FindFirstFileA,FindClose, | 0_2_00405E9C |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_0040264F FindFirstFileA, | 0_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_0040264F FindFirstFileA, | 12_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 12_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_00405E9C FindFirstFileA,FindClose, | 12_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 13_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_00405E9C FindFirstFileA,FindClose, | 13_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_0040264F FindFirstFileA, | 13_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 15_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_00405E9C FindFirstFileA,FindClose, | 15_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_0040264F FindFirstFileA, | 15_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 16_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_00405E9C FindFirstFileA,FindClose, | 16_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_0040264F FindFirstFileA, | 16_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 17_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_00405E9C FindFirstFileA,FindClose, | 17_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_0040264F FindFirstFileA, | 17_2_0040264F |
Source: remcos.exe, remcos.exe, 00000011.00000000.2380438690.0000000000409000.00000008.00000001.01000000.0000000A.sdmp, remcos.exe, 00000011.00000002.2503857103.0000000000409000.00000004.00000001.01000000.0000000A.sdmp, Payment slip_pdf.pif.exe | String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: Payment slip_pdf.pif.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://apis.google.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005625000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://drive.google.com/ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2165121027.0000000034C90000.00000004.00001000.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005641000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://drive.google.com/uc?export=download&id=1tGFKOOy5IKzQd8rTIWKS81wv12OARueJ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005671000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://drive.usercontent.google.com/ |
Source: Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.0000000005641000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://drive.usercontent.google.com/download?id=1tGFKOOy5IKzQd8rTIWKS81wv12OARueJ&export=download |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ssl.gstatic.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.googletagmanager.com |
Source: Payment slip_pdf.pif.exe, 0000000C.00000003.2016668250.0000000005677000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000002.2108185461.000000000565D000.00000004.00000020.00020000.00000000.sdmp, Payment slip_pdf.pif.exe, 0000000C.00000003.2016611503.0000000005677000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.com |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 0_2_0040310B |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 12_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 13_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 15_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 16_2_0040310B |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_0040310B EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, | 17_2_0040310B |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\ProgramData\Remcos\remcos.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 0_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_00405E9C FindFirstFileA,FindClose, | 0_2_00405E9C |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 0_2_0040264F FindFirstFileA, | 0_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_0040264F FindFirstFileA, | 12_2_0040264F |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 12_2_00405475 |
Source: C:\Users\user\Desktop\Payment slip_pdf.pif.exe | Code function: 12_2_00405E9C FindFirstFileA,FindClose, | 12_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 13_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_00405E9C FindFirstFileA,FindClose, | 13_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 13_2_0040264F FindFirstFileA, | 13_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 15_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_00405E9C FindFirstFileA,FindClose, | 15_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 15_2_0040264F FindFirstFileA, | 15_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 16_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_00405E9C FindFirstFileA,FindClose, | 16_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 16_2_0040264F FindFirstFileA, | 16_2_0040264F |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_00405475 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, | 17_2_00405475 |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_00405E9C FindFirstFileA,FindClose, | 17_2_00405E9C |
Source: C:\ProgramData\Remcos\remcos.exe | Code function: 17_2_0040264F FindFirstFileA, | 17_2_0040264F |