Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0016-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0018-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0019-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-001b-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.en\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.es\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.fr\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0044-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0090-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-00a1-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-00ba-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-00e1-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-00e2-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0115-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0116-0409-1000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0117-0409-0000-0000000ff1ce}-c\access.en-us\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-0117-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\msocache\all users\{90160000-012b-0409-0000-0000000ff1ce}-c\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\default\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\desktop\bpmlnobvsb\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\desktop\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\desktop\nikhqaiqau\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\desktop\zbedcjpbey\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\documents\bpmlnobvsb\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\documents\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\documents\nikhqaiqau\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\documents\zbedcjpbey\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\downloads\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\favorites\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\user\searches\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | File created: c:\users\public\libraries\how-to-decrypt-gn9cj.txt | Jump to behavior |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140004DE4 lstrlenW,HeapAlloc,PathFindFileNameW,lstrcpyW,ZwClose,lstrcpyW,HeapFree, | 0_2_0000000140004DE4 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140008FD8 RtlInitUnicodeString,RtlpNtOpenKey,RtlNtStatusToDosError,NtEnumerateKey,RtlNtStatusToDosError,NtClose, | 0_2_0000000140008FD8 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401B8494 RtlDosPathNameToNtPathName_U,HeapAlloc,RtlDosPathNameToNtPathName_U,ZwSetInformationFile,RtlNtStatusToDosError,ZwClose,HeapFree,RtlFreeUnicodeString, | 0_2_00000001401B8494 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_000000014000293C ZwQueryVirtualMemory,HeapAlloc,ZwQueryVirtualMemory,RtlNtStatusToDosError,HeapFree,RtlNtStatusToDosError, | 0_2_000000014000293C |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401C0D0F lstrcatW,RtlDosPathNameToNtPathName_U,RtlDosPathNameToNtPathName_U,ZwClose, | 0_2_00000001401C0D0F |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401B8D30 EnterCriticalSection,HeapFree,LeaveCriticalSection,DeleteCriticalSection,ZwClose, | 0_2_00000001401B8D30 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BC979 ZwQueryInformationFile,ZwSetInformationFile,RtlNtStatusToDosError, | 0_2_00000001401BC979 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401C296F RtlDosPathNameToNtPathName_U,ZwSetInformationFile,RtlNtStatusToDosError,ZwClose, | 0_2_00000001401C296F |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BF96E ZwQueryInformationFile,RtlNtStatusToDosError,ZwSetInformationFile,RtlNtStatusToDosError, | 0_2_00000001401BF96E |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BB247 ZwCreateEvent, | 0_2_00000001401BB247 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BFA90 ZwCreateSection,ZwMapViewOfSection,RtlNtStatusToDosError,ZwClose,RtlNtStatusToDosError,ZwUnmapViewOfSection,ZwMapViewOfSection,RtlNtStatusToDosError,ZwUnmapViewOfSection,ZwClose, | 0_2_00000001401BFA90 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001400082B0 PathCombineW,PathCombineW,HeapFree,StrTrimW,_wcslwr,_wcslwr,lstrcmpW,StrTrimW,lstrlenW,lstrlenW,HeapAlloc,_wcslwr,lstrcpyW,lstrcpyW,HeapFree,lstrcmpW,lstrcmpW,StrTrimW,StrTrimW,lstrcmpW,_snwprintf,_snwprintf,ZwClose, | 0_2_00000001400082B0 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401B6AA9 ZwCreateFile,RtlNtStatusToDosError,ZwQueryDirectoryFile,RtlNtStatusToDosError,WaitForSingleObject,ZwClose,HeapFree, | 0_2_00000001401B6AA9 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BBADF ZwWriteFile,RtlNtStatusToDosError, | 0_2_00000001401BBADF |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BD6E7 HeapAlloc,RtlDosPathNameToNtPathName_U,ZwSetInformationFile,RtlNtStatusToDosError,ZwClose,HeapFree, | 0_2_00000001401BD6E7 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401C2B01 ZwCreateFile,RtlNtStatusToDosError,RtlFreeUnicodeString, | 0_2_00000001401C2B01 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BA75C RtlDosPathNameToNtPathName_U,GetFileAttributesW,SetFileAttributesW,RtlDosPathNameToNtPathName_U,HeapAlloc,HeapFree,ZwClose,SetFileAttributesW, | 0_2_00000001401BA75C |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401C0FD6 ZwQueryInformationFile,RtlNtStatusToDosError, | 0_2_00000001401C0FD6 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401B8494 RtlDosPathNameToNtPathName_U,RtlAllocateHeap,RtlDosPathNameToNtPathName_U,NtSetInformationFile,RtlNtStatusToDosError,NtClose,HeapFree,RtlFreeUnicodeString, | 1_2_00000001401B8494 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BC979 ZwQueryInformationFile,NtSetInformationFile,RtlNtStatusToDosError, | 1_2_00000001401BC979 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401C296F RtlDosPathNameToNtPathName_U,NtSetInformationFile,RtlNtStatusToDosError,ZwClose, | 1_2_00000001401C296F |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BF96E ZwQueryInformationFile,RtlNtStatusToDosError,NtSetInformationFile,RtlNtStatusToDosError, | 1_2_00000001401BF96E |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BFA90 ZwCreateSection,NtMapViewOfSection,RtlNtStatusToDosError,ZwClose,RtlNtStatusToDosError,NtUnmapViewOfSection,ZwMapViewOfSection,RtlNtStatusToDosError,ZwUnmapViewOfSection,NtClose, | 1_2_00000001401BFA90 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401B6AA9 NtCreateFile,RtlNtStatusToDosError,NtQueryDirectoryFile,RtlNtStatusToDosError,WaitForSingleObject,NtClose,RtlReleasePrivilege, | 1_2_00000001401B6AA9 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BBADF NtWriteFile,RtlNtStatusToDosError, | 1_2_00000001401BBADF |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401C2B01 NtCreateFile,RtlNtStatusToDosError,RtlFreeUnicodeString, | 1_2_00000001401C2B01 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BA75C RtlDosPathNameToNtPathName_U,GetFileAttributesW,SetFileAttributesW,RtlDosPathNameToNtPathName_U,RtlAllocateHeap,HeapFree,NtClose,SetFileAttributesW, | 1_2_00000001401BA75C |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_0000000140004DE4 lstrlenW,RtlAllocateHeap,PathFindFileNameW,lstrcpyW,ZwClose,lstrcpyW,HeapFree, | 1_2_0000000140004DE4 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_0000000140008FD8 RtlInitUnicodeString,RtlpNtOpenKey,RtlNtStatusToDosError,NtEnumerateKey,RtlNtStatusToDosError,NtClose, | 1_2_0000000140008FD8 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_000000014000293C ZwQueryVirtualMemory,HeapAlloc,ZwQueryVirtualMemory,RtlNtStatusToDosError,HeapFree,RtlNtStatusToDosError, | 1_2_000000014000293C |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401C0D0F lstrcatW,RtlDosPathNameToNtPathName_U,RtlDosPathNameToNtPathName_U,ZwClose, | 1_2_00000001401C0D0F |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401B8D30 EnterCriticalSection,HeapFree,LeaveCriticalSection,DeleteCriticalSection,ZwClose, | 1_2_00000001401B8D30 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BB247 ZwCreateEvent, | 1_2_00000001401BB247 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001400082B0 PathCombineW,PathCombineW,HeapFree,StrTrimW,_wcslwr,_wcslwr,lstrcmpW,StrTrimW,lstrlenW,lstrlenW,HeapAlloc,_wcslwr,lstrcpyW,lstrcpyW,HeapFree,lstrcmpW,lstrcmpW,StrTrimW,StrTrimW,lstrcmpW,_snwprintf,_snwprintf,ZwClose, | 1_2_00000001400082B0 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BD6E7 HeapAlloc,RtlDosPathNameToNtPathName_U,ZwSetInformationFile,RtlNtStatusToDosError,ZwClose,HeapFree, | 1_2_00000001401BD6E7 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401C0FD6 ZwQueryInformationFile,RtlNtStatusToDosError, | 1_2_00000001401C0FD6 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BDDA1 | 0_2_00000001401BDDA1 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401B6AA9 | 0_2_00000001401B6AA9 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001400032D8 | 0_2_00000001400032D8 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BA75C | 0_2_00000001401BA75C |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140009754 | 0_2_0000000140009754 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140006BC8 | 0_2_0000000140006BC8 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401BBFD5 | 0_2_00000001401BBFD5 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401B6AA9 | 1_2_00000001401B6AA9 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BA75C | 1_2_00000001401BA75C |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BDDA1 | 1_2_00000001401BDDA1 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001400032D8 | 1_2_00000001400032D8 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_0000000140009754 | 1_2_0000000140009754 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_0000000140006BC8 | 1_2_0000000140006BC8 |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Code function: 1_2_00000001401BBFD5 | 1_2_00000001401BBFD5 |
Source: unknown | Process created: C:\Users\user\Desktop\Q1xEDBAmY5.exe 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' | |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Process created: C:\Users\user\AppData\Roaming\TextNotepad\Unistore C:\Users\user\AppData\Roaming\TextNotepad\Unistore /go | |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Process created: C:\Windows\System32\cmd.exe cmd /c waitfor /t 10 pause /d y & attrib -h 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' & del 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' & rd 'C:\Users\user\AppData\Roaming\TextNotepad\' | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\waitfor.exe waitfor /t 10 pause /d y | |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Process created: C:\Windows\System32\cmd.exe cmd /c waitfor /t 10 pause /d y & attrib -h 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' & del 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' & rd 'C:\Users\user\Desktop\' | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\attrib.exe attrib -h 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\waitfor.exe waitfor /t 10 pause /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\attrib.exe attrib -h 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' | |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Process created: C:\Users\user\AppData\Roaming\TextNotepad\Unistore C:\Users\user\AppData\Roaming\TextNotepad\Unistore /go | Jump to behavior |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Process created: C:\Windows\System32\cmd.exe cmd /c waitfor /t 10 pause /d y & attrib -h 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' & del 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' & rd 'C:\Users\user\Desktop\' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Process created: C:\Windows\System32\cmd.exe cmd /c waitfor /t 10 pause /d y & attrib -h 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' & del 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' & rd 'C:\Users\user\AppData\Roaming\TextNotepad\' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\waitfor.exe waitfor /t 10 pause /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\attrib.exe attrib -h 'C:\Users\user\AppData\Roaming\TextNotepad\Unistore' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\waitfor.exe waitfor /t 10 pause /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\attrib.exe attrib -h 'C:\Users\user\Desktop\Q1xEDBAmY5.exe' | Jump to behavior |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_000000014000E00A push rdi; ret | 0_2_000000014000E00B |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140016CE6 push rcx; retf | 0_2_0000000140016CF1 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001401B8D30 push qword ptr [000000014000B0A0h]; ret | 0_2_00000001401B8EA1 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_000000014001927A push rbp; iretd | 0_2_000000014001928A |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_00000001400AE6A0 push qword ptr [000000014000B328h]; ret | 0_2_00000001400AE6A6 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140017E9F push rdi; retf | 0_2_0000000140017EAE |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_000000014009B6D7 push qword ptr [000000014000B330h]; ret | 0_2_000000014009B6DD |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0000000140007BDD push rax; ret | 0_2_0000000140007BE6 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02103A1F push edx; ret | 0_2_02103A22 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02105A04 push FA262755h; retf | 0_2_02105A0B |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_021062D4 push ecx; ret | 0_2_021062FD |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_021052C6 push edx; iretd | 0_2_021052D0 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02102360 push ecx; ret | 0_2_02102389 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210238B push ecx; ret | 0_2_02102389 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02104BDE push ecx; ret | 0_2_02104BE1 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02108BFD push ecx; ret | 0_2_02108C19 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210600B push ecx; iretd | 0_2_02106040 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210502E push ecx; ret | 0_2_02105045 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210384E push ebp; ret | 0_2_02103858 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_021050E2 push ebp; iretd | 0_2_02105158 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02107135 push 2E52FD49h; ret | 0_2_02107153 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210293E push edx; ret | 0_2_02102985 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02105123 push ebp; iretd | 0_2_02105158 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02105190 push ebp; iretd | 0_2_02105158 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_021061AE push eax; retf | 0_2_021061BB |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210364E push 6879ACCAh; iretd | 0_2_02103667 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02109EA3 push es; retf | 0_2_02109EA8 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_0210876D push esi; ret | 0_2_021087A7 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02108791 push esi; ret | 0_2_021087A7 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_02108F99 push ebx; ret | 0_2_02108F9A |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Code function: 0_2_021047CD push 9D6EFE5Dh; ret | 0_2_021047D3 |
Source: C:\Users\user\Desktop\Q1xEDBAmY5.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\waitfor.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\waitfor.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\waitfor.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\waitfor.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\Default\Documents | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\BNAGMGSPLO | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\BPMLNOBVSB | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\IPKGELNTQY | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\LSBIHQFDVT | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\NIKHQAIQAU | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\PWCCAWLGRE | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\WKXEWIOTXI | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\ZBEDCJPBEY | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\user\Documents\ZTGJILHXQB | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\TextNotepad\Unistore | Directory queried: C:\Users\Public\Documents | Jump to behavior |