Source: 4019223246.exe, 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: 4019223246.exe, 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: 4019223246.exe, 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp | String found in binary or memory: http://qpQMsG.com |
Source: 4019223246.exe, 00000001.00000002.658704693.0000000002C41000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: 4019223246.exe, 00000004.00000002.913312856.0000000002ED4000.00000004.00000001.sdmp | String found in binary or memory: http://wg3NmRd1lkGGL4Op.org |
Source: 4019223246.exe, 00000004.00000002.913312856.0000000002ED4000.00000004.00000001.sdmp | String found in binary or memory: http://wg3NmRd1lkGGL4Op.orghb |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css |
Source: 4019223246.exe, 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 1_2_012FCF78 | 1_2_012FCF78 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 1_2_012F9754 | 1_2_012F9754 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 1_2_012F9F80 | 1_2_012F9F80 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00406C50 | 4_2_00406C50 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00402860 | 4_2_00402860 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0041A47E | 4_2_0041A47E |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00408C10 | 4_2_00408C10 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00418C8C | 4_2_00418C8C |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401650 | 4_2_00401650 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00418204 | 4_2_00418204 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00402ED0 | 4_2_00402ED0 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00402B40 | 4_2_00402B40 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00418748 | 4_2_00418748 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00407350 | 4_2_00407350 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00402F39 | 4_2_00402F39 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0040DBD1 | 4_2_0040DBD1 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00407BEF | 4_2_00407BEF |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00419384 | 4_2_00419384 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_026C8F4B | 4_2_026C8F4B |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameAsyncState.dllF vs 4019223246.exe |
Source: 4019223246.exe, 00000001.00000002.662251646.0000000005EF6000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameObjectIDGenerator.exe< vs 4019223246.exe |
Source: 4019223246.exe, 00000001.00000002.661981197.0000000005E70000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameLegacyPathHandling.dllN vs 4019223246.exe |
Source: 4019223246.exe, 00000001.00000002.662685824.0000000006720000.00000002.00000001.sdmp | Binary or memory string: originalfilename vs 4019223246.exe |
Source: 4019223246.exe, 00000001.00000002.662685824.0000000006720000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs 4019223246.exe |
Source: 4019223246.exe, 00000001.00000002.662459335.0000000006620000.00000002.00000001.sdmp | Binary or memory string: System.OriginalFileName vs 4019223246.exe |
Source: 4019223246.exe, 00000004.00000003.657876207.0000000000C2F000.00000004.00000001.sdmp | Binary or memory string: OriginalFilename_.dll4 vs 4019223246.exe |
Source: 4019223246.exe, 00000004.00000000.656009800.000000000054E000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameObjectIDGenerator.exe< vs 4019223246.exe |
Source: 4019223246.exe, 00000004.00000002.914172803.0000000003E21000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameVYolEChnIaesWIMZgVfbCHvjTeMwVa.exe4 vs 4019223246.exe |
Source: 4019223246.exe, 00000004.00000002.914766360.00000000051B0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenameKernelbase.dll.muij% vs 4019223246.exe |
Source: 4019223246.exe | Binary or memory string: OriginalFilenameObjectIDGenerator.exe< vs 4019223246.exe |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 1_2_00858D0C push es; iretd | 1_2_00858F8B |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0041C40C push cs; iretd | 4_2_0041C4E2 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00423149 push eax; ret | 4_2_00423179 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0041C50E push cs; iretd | 4_2_0041C4E2 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_004231C8 push eax; ret | 4_2_00423179 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0040E1DD push ecx; ret | 4_2_0040E1F0 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_004211B8 push ebx; retf | 4_2_004211B9 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0041C6BE push ebx; ret | 4_2_0041C6BF |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00468D0C push es; iretd | 4_2_00468F8B |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_026C9974 push ebp; iretd | 4_2_026C9975 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_026C2C60 push edi; ret | 4_2_026C2C76 |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Function Chain: systemQueried,threadCreated,threadResumed,threadDelayed,threadDelayed,threadDelayed,systemQueried,systemQueried,systemQueried,threadDelayed,systemQueried,threadDelayed,threadDelayed,systemQueried,threadDelayed,systemQueried,threadDelayed,threadDelayed,processSet,processSet,memAlloc,memAlloc,memAlloc,memAlloc,threadDelayed |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: 4019223246.exe, 00000004.00000002.914766360.00000000051B0000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | Binary or memory string: vmware |
Source: 4019223246.exe, 00000004.00000002.912265760.0000000000C57000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: 4019223246.exe, 00000004.00000002.914766360.00000000051B0000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: 4019223246.exe, 00000004.00000002.914766360.00000000051B0000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | Binary or memory string: VMware SVGA II |
Source: 4019223246.exe, 00000001.00000002.658750521.0000000002C95000.00000004.00000001.sdmp | Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools |
Source: 4019223246.exe, 00000004.00000002.914766360.00000000051B0000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0040CDC9 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 4_2_0040CDC9 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_0040E5DC _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 4_2_0040E5DC |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00416F2A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 4_2_00416F2A |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_004123B1 SetUnhandledExceptionFilter, | 4_2_004123B1 |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Users\user\Desktop\4019223246.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4019223246.exe | Queries volume information: C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation | Jump to behavior |
Source: Yara match | File source: 00000004.00000002.913312856.0000000002ED4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.914172803.0000000003E21000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.914560852.0000000004FE0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.657508762.0000000000BE4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.912388878.00000000025A2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.912715120.00000000029F0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: 4019223246.exe PID: 6104, type: MEMORY |
Source: Yara match | File source: 4.2.4019223246.exe.25e301e.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e23258.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e24140.10.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e2136.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.4019223246.exe.be4648.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e2136.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.4019223246.exe.be4648.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.4fe0000.11.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0ee8.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e73010.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e301e.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e23258.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e73010.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e24140.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0ee8.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.4fe0000.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000004.00000002.913312856.0000000002ED4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.914172803.0000000003E21000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.914560852.0000000004FE0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.913196902.0000000002E21000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.657508762.0000000000BE4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.912388878.00000000025A2000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.912715120.00000000029F0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: 4019223246.exe PID: 6104, type: MEMORY |
Source: Yara match | File source: 4.2.4019223246.exe.25e301e.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e23258.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e24140.10.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e2136.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.4019223246.exe.be4648.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e2136.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.4019223246.exe.be4648.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.4fe0000.11.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0ee8.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e73010.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.25e301e.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e23258.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e73010.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.3e24140.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.29f0ee8.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.4019223246.exe.4fe0000.11.raw.unpack, type: UNPACKEDPE |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401980 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401980 |
Source: C:\Users\user\Desktop\4019223246.exe | Code function: 4_2_00401EB6 _memset,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,CorBindToRuntimeEx,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,InterlockedDecrement,InterlockedDecrement,SysFreeString,VariantClear,InterlockedDecrement,SysFreeString, | 4_2_00401EB6 |