Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00456180 _wcschr,_wcschr,GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_00456180 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004774C0 _wcschr,_wcschr,_wcschr,FindFirstFileW,FindClose,_wcschr,FindFirstFileW,FindClose, | 0_2_004774C0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004440A0 FindFirstFileW,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose, | 0_2_004440A0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0042E210 FindFirstFileW,FindNextFileW,FindClose,GetTickCount,__wcstoi64,FindNextFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose, | 0_2_0042E210 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00444380 FindFirstFileW,GetLastError,FindClose,FileTimeToLocalFileTime, | 0_2_00444380 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00477430 FindFirstFileW,FindClose,GetFileAttributesW, | 0_2_00477430 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004446C0 CreateFileW,GetFileSizeEx,CloseHandle,FindFirstFileW,GetLastError,FindClose,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z, | 0_2_004446C0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00455C10 GetFullPathNameW,GetFullPathNameW,GetFullPathNameW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,_wcsrchr,_wcsrchr,_wcsncpy,GetTickCount,PeekMessageW,GetTickCount,MoveFileW,DeleteFileW,MoveFileW,GetLastError,CopyFileW,GetLastError,FindNextFileW,FindClose, | 0_2_00455C10 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00472DE0 FindFirstFileW,FindClose,GetFileAttributesW,CreateFileW,WriteFile,WriteFile,WriteFile,CloseHandle, | 0_2_00472DE0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00454FA0 _wcschr,_wcschr,GetFileAttributesW,FindFirstFileW,FindClose,CoInitialize,CoCreateInstance,CoUninitialize, | 0_2_00454FA0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004013F4 GlobalUnlock,CloseClipboard,SetTimer,GetTickCount,GetTickCount,GetMessageW,GetTickCount,GetFocus,TranslateAcceleratorW,GetKeyState,GetWindowLongW,IsWindowEnabled,GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,IsDialogMessageW,ShowWindow,GetForegroundWindow,GetWindowThreadProcessId,GetClassNameW,KillTimer,DragQueryFileW,DragFinish,GetTickCount,DragFinish,DragFinish,_wcsncpy,_wcsncpy,GetTickCount,_wcsncpy,GetTickCount,IsDialogMessageW,SetCurrentDirectoryW,TranslateAcceleratorW,TranslateMessage,DispatchMessageW, | 0_2_004013F4 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040F520 __wcsnicmp,__wcsnicmp,GetWindowThreadProcessId,AttachThreadInput,GetKeyboardLayout,GetTickCount,GetCurrentThreadId,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetGUIThreadInfo,GetWindowThreadProcessId,GetTickCount,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,__wcsnicmp,_wcschr,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsicoll,PostMessageW,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,__wcsnicmp,__wcsnicmp,__fassign,PostMessageW,PostMessageW,PostMessageW,__itow,PostMessageW,_free,GetTickCount,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetForegroundWindow,GetWindowThreadProcessId, | 0_2_0040F520 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040F956 GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,_free,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput, | 0_2_0040F956 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00412DD0 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetKeyState, | 0_2_00412DD0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004013F4 | 0_2_004013F4 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040F520 | 0_2_0040F520 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0049F010 | 0_2_0049F010 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0049B08C | 0_2_0049B08C |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00460170 | 0_2_00460170 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040C1E0 | 0_2_0040C1E0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0049D1F1 | 0_2_0049D1F1 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00448260 | 0_2_00448260 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0047F260 | 0_2_0047F260 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00408290 | 0_2_00408290 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0042F2A0 | 0_2_0042F2A0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00420490 | 0_2_00420490 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00442570 | 0_2_00442570 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004925B2 | 0_2_004925B2 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0048E600 | 0_2_0048E600 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004186B0 | 0_2_004186B0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00482755 | 0_2_00482755 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0041C700 | 0_2_0041C700 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004897EE | 0_2_004897EE |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043A7A0 | 0_2_0043A7A0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043F870 | 0_2_0043F870 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040C800 | 0_2_0040C800 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0049D8CD | 0_2_0049D8CD |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00484970 | 0_2_00484970 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004829C5 | 0_2_004829C5 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004999EF | 0_2_004999EF |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0040DA40 | 0_2_0040DA40 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00496A05 | 0_2_00496A05 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00414AC0 | 0_2_00414AC0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00432DD0 | 0_2_00432DD0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00401DE0 | 0_2_00401DE0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00481E4B | 0_2_00481E4B |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00499F40 | 0_2_00499F40 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00475F00 | 0_2_00475F00 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00407FC0 | 0_2_00407FC0 |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Section loaded: kbdsg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.logon.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xamlhost.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xaml.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xaml.controls.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00460170 MulDiv,MulDiv,MulDiv,_wcschr,__wcsicoll,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,_wcschr,DrawTextW,DrawTextW,GetCharABCWidthsW,MulDiv,GetSystemMetrics,GetSystemMetrics,MulDiv,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetWindowLongW,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW,CreateWindowExW,CreateWindowExW,CreateWindowExW,CreateWindowExW,GetWindowLongW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,CreateWindowExW,SendMessageW,CreateWindowExW,SendMessageW,SendMessageW,MulDiv,MulDiv,MulDiv,MoveWindow,SelectObject,ReleaseDC,SendMessageW,SendMessageW,GetClientRect,SetWindowLongW,SendMessageW,SetWindowLongW,MoveWindow,GetWindowRect,SendMessageW,SetWindowPos,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos,MapWindowPoints, | 0_2_00460170 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00453120 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,CreateDCW,GetDC,GetPixel,DeleteDC,ReleaseDC, | 0_2_00453120 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0047A3E0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 0_2_0047A3E0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00463410 GetWindowLongW,GetWindowLongW,GetWindowLongW,__wcsnicmp,__wcsnicmp,__wcsicoll,SetWindowPos,__wcsicoll,__wcsicoll,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,EnableWindow,__wcsnicmp,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,__wcsnicmp,MulDiv,MulDiv,__wcsnicmp,MulDiv,MulDiv,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcstoi64,IsWindow,SetParent,SetWindowLongW,SetParent,IsWindowVisible,IsIconic,SetWindowLongW,SetWindowLongW,SetWindowPos,InvalidateRect, | 0_2_00463410 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00439490 GetForegroundWindow,IsWindowVisible,GetWindowThreadProcessId,IsZoomed,IsIconic,GetWindowLongW,GetModuleHandleW,GetProcAddress, | 0_2_00439490 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0047A520 GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,SetForegroundWindow,SetForegroundWindow,GetForegroundWindow,GetWindow,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 0_2_0047A520 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0046A590 SendMessageW,SendMessageW,SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,PtInRect,SetFocus,SendMessageW,SendMessageW,ShowWindow,SetFocus,InvalidateRect,InvalidateRect,InvalidateRect,MapWindowPoints,InvalidateRect, | 0_2_0046A590 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 0_2_00466740 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 0_2_00466740 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043A7A0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,SelectObject,DeleteDC,DeleteObject,_free,GetPixel,ReleaseDC, | 0_2_0043A7A0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043D800 GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,WindowFromPoint,EnumChildWindows,_memset,EnumChildWindows,GetClassNameW,EnumChildWindows, | 0_2_0043D800 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043C970 SendMessageW,SendMessageW,SendMessageW,IsWindowVisible,ShowWindow,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageW, | 0_2_0043C970 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00477AB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 0_2_00477AB0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00477B10 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 0_2_00477B10 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0043AFB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_wcsrchr,__wcsicoll,__wcsicoll,__wcsicoll,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,__wcsnicmp,__fassign,__wcsnicmp,_wcsncpy,__fassign,__fassign,__fassign,__fassign,GetDC,DestroyIcon,DeleteObject,DeleteObject,GetIconInfo,DeleteObject,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject,_free,_free,_free, | 0_2_0043AFB0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00456180 _wcschr,_wcschr,GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_00456180 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004774C0 _wcschr,_wcschr,_wcschr,FindFirstFileW,FindClose,_wcschr,FindFirstFileW,FindClose, | 0_2_004774C0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004440A0 FindFirstFileW,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose, | 0_2_004440A0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_0042E210 FindFirstFileW,FindNextFileW,FindClose,GetTickCount,__wcstoi64,FindNextFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose, | 0_2_0042E210 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00444380 FindFirstFileW,GetLastError,FindClose,FileTimeToLocalFileTime, | 0_2_00444380 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00477430 FindFirstFileW,FindClose,GetFileAttributesW, | 0_2_00477430 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_004446C0 CreateFileW,GetFileSizeEx,CloseHandle,FindFirstFileW,GetLastError,FindClose,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z, | 0_2_004446C0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00455C10 GetFullPathNameW,GetFullPathNameW,GetFullPathNameW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,_wcsrchr,_wcsrchr,_wcsncpy,GetTickCount,PeekMessageW,GetTickCount,MoveFileW,DeleteFileW,MoveFileW,GetLastError,CopyFileW,GetLastError,FindNextFileW,FindClose, | 0_2_00455C10 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00472DE0 FindFirstFileW,FindClose,GetFileAttributesW,CreateFileW,WriteFile,WriteFile,WriteFile,CloseHandle, | 0_2_00472DE0 |
Source: C:\Users\user\Desktop\The Earth.exe | Code function: 0_2_00454FA0 _wcschr,_wcschr,GetFileAttributesW,FindFirstFileW,FindClose,CoInitialize,CoCreateInstance,CoUninitialize, | 0_2_00454FA0 |