Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.220.101.205 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.147.140.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.244.90 |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730F00000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17B307000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://.css |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730F00000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17B307000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://.jpg |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3mzmrus2oron5fxptw7hw2puho3bnqmw2hqy7nw64dsrrjwdilva.b32.i2p/cgi-bin/query?hostname= |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://7tbay5p4kzeekxvyvbf6v7eauazemsnnl2aoyqhg5jzpr5eke7tq.b32.i2p/cgi-bin/jump.cgi?a= |
Source: svchost.exe, 00000001.00000002.2839166022.00000231D4CA4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.ver) |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acosgr5ufcefr7w7nv4v6k4ebdda_117.0.5938.132/117.0.5 |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/ |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567 |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20 |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730F00000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17B307000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://html4/loose.dtd |
Source: TbQwNs1NS7.exe, 0000000C.00000003.1647081324.000002A17A41A000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077506724.000002A17A3AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/ |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077506724.000002A17A3AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/ar |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2247525188.000002A17A41C000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077707571.000002A17A41C000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000003.2247770903.000002A17A41C000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000003.1647081324.000002A17A41A000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000003.2247383961.000002A17A417000.00000004.00000020.00020000.00000000.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077506724.000002A17A3AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line?fields=query |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077506724.000002A17A3AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line?fields=queryfirs |
Source: TbQwNs1NS7.exe, 0000000C.00000003.1647081324.000002A17A41A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/n |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077506724.000002A17A3AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com:80/line?fields=queryw |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://nytzrhrjjfsutowojvxi7hphesskpqqr65wpistz6wa7cpajhp7a.b32.i2p/cgi-bin/jump.cgi?q= |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://reg.i2p/hosts.txt |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/add |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txt |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/jump/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/jump/reg.i2phttp://3mzmrus2oron5 |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://2019.www.torproject.org/docs/faq.html.en#WarningsAboutSOCKSandDNSInformationLeaks.%s |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://banana.incognet.io/ |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://blog.torproject.org/lifecycle-of-a-new-relay |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://blog.torproject.org/lifecycle-of-a-new-relayset |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://blog.torproject.org/v2-deprecation-timeline |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bridges.torproject.org/status?id=%s |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bridges.torproject.org/status?id=%suninitialized |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/14917. |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/21155. |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/8742. |
Source: svchost.exe, 00000013.00000003.1364460115.000001280F66E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000013.00000003.1364460115.000001280F66E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Transit/Stops/ |
Source: svchost.exe, 00000013.00000003.1364460115.000001280F66E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.t |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://freehaven.net/anonbib/#hs-attack06 |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A62000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6 |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49F6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://g.live.com/odclientsettings/Prod.C: |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A62000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2 |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A43000.00000004.00000800.00020000.00000000.sdmp, svchost.exe, 00000001.00000003.1205052021.00000231D4A62000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C: |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A62000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96 |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gcc.gnu.org/bugs/): |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://i2p.ghativega.in/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://i2p.novg.net/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://i2pseed.creativecowpat.net:8443/ |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D4A62000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneclient.sfx.ms/Win/Installers/23.194.0917.0001/amd64/OneDriveSetup.exe |
Source: svchost.exe, 00000001.00000003.1205052021.00000231D49F6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe.C: |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed-fr.i2pd.xyz/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed-pl.i2pd.xyz/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed.diva.exchange/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed.i2pgit.org/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed.memcpy.io/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed.onion.im/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed.stormycloud.org/ |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://reseed2.i2p.net/ |
Source: tor.exe, 00000011.00000003.1320406588.000001811A9F0000.00000004.00000020.00020000.00000000.sdmp, tor.exe, 00000011.00000003.1336008658.000001811A9D7000.00000004.00000020.00020000.00000000.sdmp, tor.exe, 00000011.00000003.1323055516.000001811B064000.00000004.00000020.00020000.00000000.sdmp, tor.exe, 00000011.00000003.1337310374.000001811A9EE000.00000004.00000020.00020000.00000000.sdmp, tor.exe, 00000011.00000003.1315281827.000001811ABBB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sabotage.net |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://support.torproject.org/faq/staying-anonymous/ |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://support.torproject.org/faq/staying-anonymous/alphabetaThis |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.gnu.org/licenses/gpl-3.0.en.html) |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.torproject.org/ |
Source: Q3N5HdmTIp.exe, 00000000.00000002.1312784338.00007FF730500000.00000004.00000001.01000000.00000003.sdmp, TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.torproject.org/docs/faq.html#BestOSForRelay |
Source: TbQwNs1NS7.exe, 0000000C.00000002.3077766030.000002A17A907000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.torproject.org/documentation.html |
Source: TbQwNs1NS7.exe, 0000000C.00000003.2690450607.000002A17C568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www2.mk16.de/ |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FF7774E63EA | 12_2_00007FF7774E63EA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FF7774E13DA | 12_2_00007FF7774E13DA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FF7774EC300 | 12_2_00007FF7774EC300 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABAE644F | 12_2_00007FFCABAE644F |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABAE802A | 12_2_00007FFCABAE802A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABAEC9B0 | 12_2_00007FFCABAEC9B0 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABAE996A | 12_2_00007FFCABAE996A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABB0BD1A | 12_2_00007FFCABB0BD1A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABB05C84 | 12_2_00007FFCABB05C84 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABB0EDA0 | 12_2_00007FFCABB0EDA0 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABB073CA | 12_2_00007FFCABB073CA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCABB02ECA | 12_2_00007FFCABB02ECA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC15E520 | 12_2_00007FFCAC15E520 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC15D9FA | 12_2_00007FFCAC15D9FA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC156A91 | 12_2_00007FFCAC156A91 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC1582CA | 12_2_00007FFCAC1582CA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC1590DA | 12_2_00007FFCAC1590DA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC15C920 | 12_2_00007FFCAC15C920 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC161990 | 12_2_00007FFCAC161990 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC15CB22 | 12_2_00007FFCAC15CB22 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC15C79D | 12_2_00007FFCAC15C79D |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC513888 | 12_2_00007FFCAC513888 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC51D1E2 | 12_2_00007FFCAC51D1E2 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC5149C1 | 12_2_00007FFCAC5149C1 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC515E3A | 12_2_00007FFCAC515E3A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC512FAF | 12_2_00007FFCAC512FAF |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC51C4DA | 12_2_00007FFCAC51C4DA |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC520070 | 12_2_00007FFCAC520070 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAC515001 | 12_2_00007FFCAC515001 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAFBA420A | 12_2_00007FFCAFBA420A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAFBA153F | 12_2_00007FFCAFBA153F |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAFBA8C4A | 12_2_00007FFCAFBA8C4A |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAFBAEA20 | 12_2_00007FFCAFBAEA20 |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Code function: 12_2_00007FFCAFBABB71 | 12_2_00007FFCAFBABB71 |
Source: unknown | Process created: C:\Users\user\Desktop\Q3N5HdmTIp.exe "C:\Users\user\Desktop\Q3N5HdmTIp.exe" | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\taskkill.exe taskkill.exe /F /FI "SERVICES eq ConsentUI_1093b712" | |
Source: C:\Windows\System32\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe stop ConsentUI_1093b712 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe create ConsentUI_1093b712 binpath= C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe type= own start= auto error= ignore | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe failure ConsentUI_1093b712 reset= 1 actions= restart/10000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe start ConsentUI_1093b712 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\ /setowner *S-1-5-18 | |
Source: C:\Windows\System32\icacls.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public /restore C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\q2G6SUHkZHBj.acl | |
Source: C:\Windows\System32\icacls.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Process created: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe -f C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.rc | |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p | |
Source: unknown | Process created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k UnistackSvcGroup | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable | |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\taskkill.exe taskkill.exe /F /FI "SERVICES eq ConsentUI_1093b712" | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe stop ConsentUI_1093b712 | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe create ConsentUI_1093b712 binpath= C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe type= own start= auto error= ignore | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe failure ConsentUI_1093b712 reset= 1 actions= restart/10000 | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\sc.exe sc.exe start ConsentUI_1093b712 | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\ /setowner *S-1-5-18 | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Process created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public /restore C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\q2G6SUHkZHBj.acl | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Process created: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe -f C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.rc | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Q3N5HdmTIp.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: qmgr.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsperf.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: esent.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: flightsettings.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsigd.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: upnp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ssdpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsmauto.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsmsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: pcwum.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msv1_0.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntlmshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptdll.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: es.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\TbQwNs1NS7.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\Public\Fonts.{D20EA4E1-3957-11d2-A40B-0C5020524152}\tor.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: moshost.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mapsbtsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mosstorage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ztrace_maps.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ztrace_maps.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mapconfiguration.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: aphostservice.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: networkhelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdataplatformhelperutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mccspal.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: syncutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: syncutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmcfgutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmcmnutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmxmlhelputils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: inproclogger.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: flightsettings.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msv1_0.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntlmshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptdll.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: synccontroller.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: pimstore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: aphostclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: accountaccessor.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dsclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: systemeventsbrokerclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdatalanguageutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mccsengineshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cemapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdatatypehelperutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: phoneutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: storsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcd.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wer.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: storageusage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: wscapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: sppc.dll | Jump to behavior |