Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA, |
Source: DOC04121993.exe, DOC04121993.exe, 00000007.00000002.223712280.0000000000475000.00000040.00000001.sdmp | String found in binary or memory: http://127.0.0.1: |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c0 |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://cert.int-x3.letsencrypt.org/0 |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://cps.letsencrypt.org0 |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://cps.root-x1.letsencrypt.org0 |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl0 |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://isrg.trustid.ocsp.identrust.com0; |
Source: DOC04121993.exe, 00000002.00000002.468167788.0000000002C9E000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.int-x3.letsencrypt.org0/ |
Source: DOC04121993.exe, 00000002.00000002.467888799.0000000002B70000.00000004.00000001.sdmp | String found in binary or memory: http://vd2JBRKVM6n.net |
Source: DOC04121993.exe, 00000002.00000002.467655668.0000000002A92000.00000004.00000001.sdmp | String found in binary or memory: http://vd2JBRKVM6n.net$ |
Source: DOC04121993.exe, DOC04121993.exe, 00000007.00000002.223712280.0000000000475000.00000040.00000001.sdmp | String found in binary or memory: https://api.telegram.org/bot%telegramapi%/ |
Source: DOC04121993.exe | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/ |
Source: DOC04121993.exe | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: DOC04121993.exe, 00000000.00000002.199767698.0000000002705000.00000040.00000001.sdmp, DOC04121993.exe, 00000002.00000002.462629290.0000000000402000.00000040.00000001.sdmp, DOC04121993.exe, 00000005.00000002.229601884.00000000027C5000.00000040.00000001.sdmp, DOC04121993.exe, 00000007.00000002.223712280.0000000000475000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/U |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045AACC NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0044F67C GetSubMenu,SaveDC,RestoreDC,73BBB080,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00433DC8 NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0043FF18 NtdllDefWindowProc_A,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_0046E159 NtCreateSection, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_0233B362 NtQuerySystemInformation, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_0233B331 NtQuerySystemInformation, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045AACC NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0044F67C GetSubMenu,SaveDC,RestoreDC,GetWindowDC,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00433DC8 NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0043FF18 NtdllDefWindowProc_A,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045AACC NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0044F67C GetSubMenu,SaveDC,RestoreDC,GetWindowDC,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00433DC8 NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0043FF18 NtdllDefWindowProc_A,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004551A0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0044F67C |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_00467976 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_0046D13D |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3B6E8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E33468 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3702E |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E20007 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39010 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E331F8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3DBB8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39388 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E37990 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E31568 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E31D20 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3CB3F |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3810F |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3C8EB |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39CFE |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3C8AF |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E384B1 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E328B8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E348BE |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3C889 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E32099 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E37A98 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3566C |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E36A72 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3C877 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E37E78 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E36C35 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39000 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E33468 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E355D3 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3A3A2 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3DBA9 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E357AD |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E38998 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39378 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3155A |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E32136 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E3553A |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39D03 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E39D08 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_04E31D10 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE07F0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE59C8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0D10 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE7710 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE5370 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE3740 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE1CC0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE7E08 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE8648 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0DBB |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE7DF8 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE63CC |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0DCD |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE07D3 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE3731 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE7703 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE1115 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE1EA3 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE72BC |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE1CB0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE7E87 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0E93 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0CF9 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE08D6 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0A2A |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE2414 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05AE0E6A |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05B5A148 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05B5AED0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05B5EAD0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05B5BE50 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 2_2_05B5B250 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_004551A0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0044F67C |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_004551A0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0044F67C |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 7_2_00467976 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 7_2_0046D13D |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_004551A0 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_0044F67C |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00447320 push 004473ADh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00426024 push 00426050h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00428038 push 00428064h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00466080 push 004660ACh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040C090 push 0040C20Ch; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0046C150 push 0046C1C6h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00450134 push 0045019Fh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040C20E push 0040C27Fh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040C210 push 0040C27Fh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004482CC push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004262DC push 00426308h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040C2EE push 0040C31Ch; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040C2F0 push 0040C31Ch; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0041A288 push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00410324 push 00410385h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00410388 push 00410589h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0042646C push 00426498h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0044856C push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00470574 push 004705A0h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0041058C push 004106D0h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040660A push 0040665Dh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0040660C push 0040665Dh; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004106A4 push 004106D0h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0043277C push 004327A8h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004067DC push 00406808h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004327EC push 00432818h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004327B4 push 004327E0h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0044884C push 00448878h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00406854 push 00406880h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0043285C push 00432888h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00432824 push 00432850h; ret |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045AB54 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004266A4 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00442778 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_004415EC IsIconic,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00457C48 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00441E94 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045AB54 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_004266A4 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00442778 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_004415EC IsIconic,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00457C48 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00441E94 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045AB54 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_004266A4 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00442778 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_004415EC IsIconic,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00457C48 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00441E94 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_004266A4 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00442778 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_0045AB54 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_0045B248 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,DefWindowProcA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_0045B2F8 IsIconic,SetActiveWindow,IsWindowEnabled,DefWindowProcA,SetWindowPos,SetFocus, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_004415EC IsIconic,GetCapture, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00457C48 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00441E94 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -922337203685477s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -119564s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -59594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -59188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -117376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -117000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -58282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -115188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -57406s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -57188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -113000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -56282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -82782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -54094s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -103376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -103000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -75891s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -74250s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -73923s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -48188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -48000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -47094s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -46500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -92000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -66750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -43594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -63750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -63423s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -61782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -61500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -60141s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -78000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -58173s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -37688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -36594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53250s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -35282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -51282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -51000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -33594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -49641s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -32500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -32282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -48000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -47673s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -31188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -45750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30094s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -42750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -40032s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -39750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -39423s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -36750s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -31500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -81423s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -80391s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -80064s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52094s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -51876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -76782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -51000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -50094s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -49876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -49000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -48594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -47500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -47282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -46376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -69282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -45500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -67923s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -67641s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -67314s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -66282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -66000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -43782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -64641s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -64314s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -42688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -63000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -62673s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -62064s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -40688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -60423s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -39594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -39376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -58782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -38500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -38282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -57141s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -56814s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55173s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -54141s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53814s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53532s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52173s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -51891s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -47250s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -59500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -58876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -57782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -57376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -56688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55782s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -55376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -54688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -54500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -53188s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -52282s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -43376s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -39876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -33688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -33500s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -32876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -32594s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30876s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30688s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 1064 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\DOC04121993.exe TID: 5696 | Thread sleep count: 79 > 30 |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 0_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 3_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 5_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00408978 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00408A78 FindFirstFileA,GetLastError, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: 8_2_00405B54 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA, |
Source: C:\Users\user\Desktop\DOC04121993.exe | Code function: lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA, |
Source: Yara match | File source: 00000005.00000002.229601884.00000000027C5000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.462629290.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464088936.00000000009E2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.199767698.0000000002705000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464255746.0000000002242000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.223712280.0000000000475000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224265072.0000000002150000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467655668.0000000002A92000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.199649349.0000000002692000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464010082.0000000000980000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224575545.0000000002292000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000001.223334796.0000000000499000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224389648.00000000021B2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.462860776.0000000000475000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467418503.00000000029D1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467888799.0000000002B70000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 1000, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 2576, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 5080, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 1956, type: MEMORY |
Source: Yara match | File source: 7.2.DOC04121993.exe.2290000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.2240000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.2150000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.980000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.21b0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.1.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 5.2.DOC04121993.exe.2750000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.2150000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.980000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.DOC04121993.exe.2690000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.9e0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000005.00000002.229601884.00000000027C5000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.462629290.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464088936.00000000009E2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.199767698.0000000002705000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464255746.0000000002242000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.223712280.0000000000475000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224265072.0000000002150000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467655668.0000000002A92000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.199649349.0000000002692000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.464010082.0000000000980000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224575545.0000000002292000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000001.223334796.0000000000499000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.224389648.00000000021B2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.462860776.0000000000475000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467418503.00000000029D1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.467888799.0000000002B70000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 1000, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 2576, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 5080, type: MEMORY |
Source: Yara match | File source: Process Memory Space: DOC04121993.exe PID: 1956, type: MEMORY |
Source: Yara match | File source: 7.2.DOC04121993.exe.2290000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.2240000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.2150000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.980000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.21b0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.1.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 5.2.DOC04121993.exe.2750000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.2150000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.980000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.DOC04121993.exe.2690000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.DOC04121993.exe.9e0000.2.unpack, type: UNPACKEDPE |