Analysis Report PURCHASE ORDER.com

Overview

General Information

Sample Name: PURCHASE ORDER.com (renamed file extension from com to exe)
Analysis ID: 385280
MD5: 9d71011e0ef3208145dd434e229ab0e2
SHA1: ecb4b62327a724ab00bd42bf98a51db3a3977079
SHA256: 8dccc7a8d24c010a59d807148c7a6779a7f2eac86868e1cf083235d0bcce3414
Tags: FormBook
Infos:

Most interesting Screenshot:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Detected FormBook malware
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Steal Google chrome login data
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected FormBook
C2 URLs / IPs found in malware configuration
Initial sample is a PE file and has a suspicious name
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
PE file has a writeable .text section
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file access)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for execution timing, often used to detect debuggers
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to shutdown / reboot the system
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection:

barindex
Found malware configuration
Source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp Malware Configuration Extractor: FormBook {"C2 list": ["www.hollandhousedesigns.design/vns/"], "decoy": ["sparkspressworld.com", "everydayresidency.com", "thebosscollectionn.com", "milkweedmagic.com", "worklesshours.com", "romeosfurnituremadera.com", "unclepetesproduce.com", "athleticamackay.com", "9nhl.com", "powellassetmanagement.com", "jxlamp.com", "onpointpetproducts.com", "buymysoft.com", "nazertrader.com", "goprj.com", "keeptalkservice.com", "aolei1688.com", "donstackl.com", "almasorchids.com", "pj5bwn.com", "featuredshop2020.com", "connectmheduaction.com", "kcastleint.com", "quintessentialmiss.com", "forenvid.com", "vetementsbd.com", "fabrizioamadori.net", "remaxplatinumva.com", "drivecart.net", "ordertds.com", "huayuanjiajiao.com", "islamiportal.com", "innergardenhealing.space", "wlwmwntor.com", "wiitendo.com", "ceschandigarh.com", "mitchellche.com", "levaporz.com", "eraophthalmica.com", "gnzywyht.com", "bobbinsbroider.com", "pollygen.com", "xn--kbrsotocheckup-5fcc.com", "theunprofessionalpodcast.com", "lendini.site", "digitalpardis.com", "meenaveen.com", "yihuafence.com", "mercadoaria.com", "domennyarendi44.net", "juandiegopalacio.com", "meltdownfitnesstulsa.com", "xn--laclnicadelvnculo-gvbi.com", "paripartners378.com", "valadecia.com", "womenring.com", "ocarlosresolve.com", "vedicherbsindia.com", "nonnearrapate.com", "viplending.net", "angelbeatsgamingclan.com", "rigmodisc.com", "page-id-78613.com", "yapadaihindi.com"]}
Multi AV Scanner detection for submitted file
Source: PURCHASE ORDER.exe Virustotal: Detection: 11% Perma Link
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE
Machine Learning detection for dropped file
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Joe Sandbox ML: detected

Compliance:

barindex
Uses 32bit PE files
Source: PURCHASE ORDER.exe Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\INSTALL.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\FAQ.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\README.txt Jump to behavior
Source: PURCHASE ORDER.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: wscui.pdbUGP source: explorer.exe, 00000012.00000000.417250705.000000000ED20000.00000002.00000001.sdmp
Source: Binary string: wntdll.pdbUGP source: MySqlAssemblyConsole.exe, 00000002.00000002.432815804.0000000002E20000.00000040.00000001.sdmp, raserver.exe, 00000017.00000002.508514426.000000000467F000.00000040.00000001.sdmp
Source: Binary string: wntdll.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.432815804.0000000002E20000.00000040.00000001.sdmp, raserver.exe
Source: Binary string: RAServer.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.431950003.0000000000828000.00000004.00000020.sdmp
Source: Binary string: X:\sborka\12217271353800656069\workdll\release\Lib1.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.434645004.000000006DE84000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506646098.000000006E064000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.506218878.000000006E064000.00000002.00020000.sdmp
Source: Binary string: C:\output\ZPSTray\pl\vc\obj\x64\mysql_ssl_rsa_setup\AutoUpda.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.432391924.0000000000D34000.00000002.00020000.sdmp, raserver.exe, 00000017.00000002.507081713.00000000043B1000.00000004.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000000.474192177.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000000.494289920.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe.0.dr
Source: Binary string: RAServer.pdbGCTL source: MySqlAssemblyConsole.exe, 00000002.00000002.431950003.0000000000828000.00000004.00000020.sdmp
Source: Binary string: wscui.pdb source: explorer.exe, 00000012.00000000.417250705.000000000ED20000.00000002.00000001.sdmp
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040646B FindFirstFileA,FindClose, 0_2_0040646B
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_004027A1 FindFirstFileA, 0_2_004027A1
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, 0_2_004058BF

Software Vulnerabilities:

barindex
Found inlined nop instructions (likely shell or obfuscated code)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 4x nop then pop esi 2_2_00BC72DB
Source: C:\Windows\SysWOW64\raserver.exe Code function: 4x nop then pop esi 23_2_027472CF

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Source: Traffic Snort IDS: 2031453 ET TROJAN FormBook CnC Checkin (GET) 192.168.2.5:49727 -> 66.235.200.146:80
Source: Traffic Snort IDS: 2031449 ET TROJAN FormBook CnC Checkin (GET) 192.168.2.5:49727 -> 66.235.200.146:80
Source: Traffic Snort IDS: 2031412 ET TROJAN FormBook CnC Checkin (GET) 192.168.2.5:49727 -> 66.235.200.146:80
C2 URLs / IPs found in malware configuration
Source: Malware configuration extractor URLs: www.hollandhousedesigns.design/vns/
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://fontfabrik.com
Source: PURCHASE ORDER.exe String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: PURCHASE ORDER.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://static-global-s-msn-com.akamaized.net/hp-neu/sc/2b/a5ea21.ico
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.fonts.com
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/?ocid=iehp
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/?ocid=iehp/
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/?ocid=iehp=
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/?ocid=iehpA7Ef
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/?ocid=iehpwsLMEM
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/de-ch/?ocid=iehpLMEMh
Source: raserver.exe, 00000017.00000002.503366099.00000000002A7000.00000004.00000020.sdmp String found in binary or memory: http://www.msn.com/de-ch/ocid=iehp
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: http://www.msn.com/ocid=iehp&
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.sakkal.com
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.tiro.com
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.typography.netD
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: explorer.exe, 00000012.00000000.414574884.000000000BC36000.00000002.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp, raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://2542116.fls.doubleclick.net/activityi;src=2542116;type=2542116;cat=chom0;ord=4842492154761;g
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp, raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://2542116.fls.doubleclick.net/activityi;src=2542116;type=chrom322;cat=chrom01g;ord=58648497779
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp, raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://2542116.fls.doubleclick.net/activityi;src=2542116;type=clien612;cat=chromx;ord=1;num=3931852
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://adservice.google.co.uk/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=5864849777998;gt
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://adservice.google.com/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=5864849777998;gtm=
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/checksync.php&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2C
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&https=1LMEM
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1LMEM
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/medianet.phpcid=8CU157172&crid=722878611&size=306x271&https=1
Source: raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://contextual.media.net/medianet.phpcid=8CU157172&crid=858412214&size=306x271&https=1
Source: raserver.exe, 00000017.00000003.449186115.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://go.microc
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1601451842&rver=6.0.5286.0&wp=MBI_SSL&wre
Source: raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://login.live.com/login.srfwa=wsignin1.0&rpsnv=11&ct=1601451842&rver=6.0.5286.0&wp=MBI_SSL&wrep
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://login.microsoftonline.com/common/oauth2/authorize?client_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://login.microsoftonline.com/common/oauth2/authorizeclient_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e3
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/.0
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/1Q
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/4
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/LMEM
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/static/images/favicons/favicon-16x16.png
Source: raserver.exe, 00000017.00000003.446049886.00000000002C5000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0LMEM
Source: raserver.exe, 00000017.00000003.446068610.00000000002E0000.00000004.00000001.sdmp String found in binary or memory: https://www.google.com/chrome/thank-you.htmlstatcb=0&installdataindex=empty&defaultbrowser=0br

Key, Mouse, Clipboard, Microphone and Screen Capturing:

barindex
Contains functionality for read data from the clipboard
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040535C GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,FindCloseChangeNotification,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_0040535C
Creates a DirectInput object (often for capturing keystrokes)
Source: MySqlAssemblyConsole.exe, 00000002.00000002.431919850.000000000081A000.00000004.00000020.sdmp Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>

E-Banking Fraud:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE

System Summary:

barindex
Detected FormBook malware
Source: C:\Windows\SysWOW64\raserver.exe Dropped file: C:\Users\user\AppData\Roaming\886N85Q4\886logri.ini Jump to dropped file
Source: C:\Windows\SysWOW64\raserver.exe Dropped file: C:\Users\user\AppData\Roaming\886N85Q4\886logrv.ini Jump to dropped file
Malicious sample detected (through community Yara rule)
Source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Initial sample is a PE file and has a suspicious name
Source: initial sample Static PE information: Filename: PURCHASE ORDER.exe
PE file has a writeable .text section
Source: MySqlAssemblyConsole.exe.0.dr Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Contains functionality to call native functions
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9D50 NtCreateFile, 2_2_00BC9D50
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9E80 NtClose, 2_2_00BC9E80
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9E00 NtReadFile, 2_2_00BC9E00
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9F30 NtAllocateVirtualMemory, 2_2_00BC9F30
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9E7C NtClose, 2_2_00BC9E7C
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC9F2D NtAllocateVirtualMemory, 2_2_00BC9F2D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9840 NtDelayExecution,LdrInitializeThunk, 23_2_045C9840
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9860 NtQuerySystemInformation,LdrInitializeThunk, 23_2_045C9860
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9540 NtReadFile,LdrInitializeThunk, 23_2_045C9540
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9560 NtWriteFile,LdrInitializeThunk, 23_2_045C9560
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9910 NtAdjustPrivilegesToken,LdrInitializeThunk, 23_2_045C9910
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C95D0 NtClose,LdrInitializeThunk, 23_2_045C95D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C99A0 NtCreateSection,LdrInitializeThunk, 23_2_045C99A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9650 NtQueryValueKey,LdrInitializeThunk, 23_2_045C9650
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9A50 NtCreateFile,LdrInitializeThunk, 23_2_045C9A50
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9660 NtAllocateVirtualMemory,LdrInitializeThunk, 23_2_045C9660
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9610 NtEnumerateValueKey,LdrInitializeThunk, 23_2_045C9610
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C96D0 NtCreateKey,LdrInitializeThunk, 23_2_045C96D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C96E0 NtFreeVirtualMemory,LdrInitializeThunk, 23_2_045C96E0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9770 NtSetInformationFile,LdrInitializeThunk, 23_2_045C9770
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9710 NtQueryInformationToken,LdrInitializeThunk, 23_2_045C9710
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9B00 NtSetValueKey,LdrInitializeThunk, 23_2_045C9B00
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9FE0 NtCreateMutant,LdrInitializeThunk, 23_2_045C9FE0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9780 NtMapViewOfSection,LdrInitializeThunk, 23_2_045C9780
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045CB040 NtSuspendThread, 23_2_045CB040
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9820 NtEnumerateKey, 23_2_045C9820
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C98F0 NtReadVirtualMemory, 23_2_045C98F0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C98A0 NtWriteVirtualMemory, 23_2_045C98A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9950 NtQueueApcThread, 23_2_045C9950
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045CAD30 NtSetContextThread, 23_2_045CAD30
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9520 NtWaitForSingleObject, 23_2_045C9520
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C99D0 NtCreateProcessEx, 23_2_045C99D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C95F0 NtQueryInformationFile, 23_2_045C95F0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9670 NtQueryInformationProcess, 23_2_045C9670
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9A10 NtQuerySection, 23_2_045C9A10
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9A00 NtProtectVirtualMemory, 23_2_045C9A00
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9A20 NtResumeThread, 23_2_045C9A20
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9A80 NtOpenDirectoryObject, 23_2_045C9A80
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045CA770 NtOpenThread, 23_2_045CA770
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9760 NtOpenProcess, 23_2_045C9760
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045CA710 NtOpenProcessToken, 23_2_045CA710
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9730 NtQueryVirtualMemory, 23_2_045C9730
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045CA3B0 NtGetContextThread, 23_2_045CA3B0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C97A0 NtUnmapViewOfSection, 23_2_045C97A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749E00 NtReadFile, 23_2_02749E00
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749E80 NtClose, 23_2_02749E80
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749F30 NtAllocateVirtualMemory, 23_2_02749F30
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749D50 NtCreateFile, 23_2_02749D50
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749E7C NtClose, 23_2_02749E7C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02749F2D NtAllocateVirtualMemory, 23_2_02749F2D
Contains functionality to shutdown / reboot the system
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_00403348
Detected potential crypto function
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_00406945 0_2_00406945
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040711C 0_2_0040711C
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB1030 2_2_00BB1030
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCD986 2_2_00BCD986
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCDAA6 2_2_00BCDAA6
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCD2D0 2_2_00BCD2D0
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCE241 2_2_00BCE241
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCDB23 2_2_00BCDB23
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCDCEB 2_2_00BCDCEB
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB2D90 2_2_00BB2D90
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB2D87 2_2_00BB2D87
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB9E30 2_2_00BB9E30
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB9E2B 2_2_00BB9E2B
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB2FB0 2_2_00BB2FB0
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BE3FA0 2_2_00BE3FA0
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCCF93 2_2_00BCCF93
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCDF20 2_2_00BCDF20
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459841F 23_2_0459841F
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641002 23_2_04641002
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459B090 23_2_0459B090
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046520A8 23_2_046520A8
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04651D55 23_2_04651D55
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458F900 23_2_0458F900
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04652D07 23_2_04652D07
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04580D20 23_2_04580D20
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459D5E0 23_2_0459D5E0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2581 23_2_045B2581
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A6E30 23_2_045A6E30
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04652EF7 23_2_04652EF7
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046522AE 23_2_046522AE
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04652B28 23_2_04652B28
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04651FF1 23_2_04651FF1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464DBD2 23_2_0464DBD2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BEBB0 23_2_045BEBB0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274E241 23_2_0274E241
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02739E30 23_2_02739E30
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02739E2B 23_2_02739E2B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02732FB0 23_2_02732FB0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02732D90 23_2_02732D90
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02732D87 23_2_02732D87
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00CCEF10 27_2_00CCEF10
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6DFBC570 28_2_6DFBC570
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E05F6EC 28_2_6E05F6EC
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E04B743 28_2_6E04B743
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E032DA0 28_2_6E032DA0
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E05F5CC 28_2_6E05F5CC
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E05A5C8 28_2_6E05A5C8
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E027260 28_2_6E027260
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6DFAD030 28_2_6DFAD030
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E04E3FF 28_2_6E04E3FF
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E0238E0 28_2_6E0238E0
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E024100 28_2_6E024100
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E05A130 28_2_6E05A130
Found potential string decryption / allocating functions
Source: C:\Windows\SysWOW64\raserver.exe Code function: String function: 0458B150 appears 35 times
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: String function: 00CA730F appears 49 times
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: String function: 6DFB9480 appears 63 times
PE file contains strange resources
Source: PURCHASE ORDER.exe Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: MySqlAssemblyConsole.exe.0.dr Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Sample file is different than original file name gathered from version info
Source: PURCHASE ORDER.exe, 00000000.00000002.239529402.0000000000730000.00000002.00000001.sdmp Binary or memory string: OriginalFilenameuser32j% vs PURCHASE ORDER.exe
Uses 32bit PE files
Source: PURCHASE ORDER.exe Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Yara signature match
Source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@11/169@0/0
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_00403348
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040460D GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA, 0_2_0040460D
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040216B CoCreateInstance,MultiByteToWideChar, 0_2_0040216B
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4612:120:WilError_01
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Local\Temp\nsb9F7B.tmp Jump to behavior
Source: PURCHASE ORDER.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: MySqlAssemblyConsole.exe, 00000002.00000002.432391924.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000000.474192177.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000000.494289920.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe.0.dr Binary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: MySqlAssemblyConsole.exe, 00000002.00000002.432391924.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000000.474192177.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000000.494289920.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe.0.dr Binary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: MySqlAssemblyConsole.exe, 00000002.00000002.432391924.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000000.474192177.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000000.494289920.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe.0.dr Binary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
Source: PURCHASE ORDER.exe Virustotal: Detection: 11%
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File read: C:\Users\user\Desktop\PURCHASE ORDER.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\PURCHASE ORDER.exe 'C:\Users\user\Desktop\PURCHASE ORDER.exe'
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe
Source: C:\Windows\explorer.exe Process created: C:\Windows\SysWOW64\raserver.exe C:\Windows\SysWOW64\raserver.exe
Source: C:\Windows\SysWOW64\raserver.exe Process created: C:\Windows\SysWOW64\cmd.exe /c copy 'C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data' 'C:\Users\user\AppData\Local\Temp\DB1' /V
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\explorer.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe 'C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe'
Source: C:\Windows\explorer.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe 'C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe'
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Jump to behavior
Source: C:\Windows\explorer.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe 'C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe' Jump to behavior
Source: C:\Windows\explorer.exe Process created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe 'C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe' Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process created: C:\Windows\SysWOW64\cmd.exe /c copy 'C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data' 'C:\Users\user\AppData\Local\Temp\DB1' /V Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe File written: C:\Users\user\AppData\Roaming\886N85Q4\886logri.ini Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\ Jump to behavior
Source: PURCHASE ORDER.exe Static file information: File size 3059224 > 1048576
Source: PURCHASE ORDER.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: wscui.pdbUGP source: explorer.exe, 00000012.00000000.417250705.000000000ED20000.00000002.00000001.sdmp
Source: Binary string: wntdll.pdbUGP source: MySqlAssemblyConsole.exe, 00000002.00000002.432815804.0000000002E20000.00000040.00000001.sdmp, raserver.exe, 00000017.00000002.508514426.000000000467F000.00000040.00000001.sdmp
Source: Binary string: wntdll.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.432815804.0000000002E20000.00000040.00000001.sdmp, raserver.exe
Source: Binary string: RAServer.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.431950003.0000000000828000.00000004.00000020.sdmp
Source: Binary string: X:\sborka\12217271353800656069\workdll\release\Lib1.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.434645004.000000006DE84000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506646098.000000006E064000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.506218878.000000006E064000.00000002.00020000.sdmp
Source: Binary string: C:\output\ZPSTray\pl\vc\obj\x64\mysql_ssl_rsa_setup\AutoUpda.pdb source: MySqlAssemblyConsole.exe, 00000002.00000002.432391924.0000000000D34000.00000002.00020000.sdmp, raserver.exe, 00000017.00000002.507081713.00000000043B1000.00000004.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000000.474192177.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000000.494289920.0000000000D34000.00000002.00020000.sdmp, MySqlAssemblyConsole.exe.0.dr
Source: Binary string: RAServer.pdbGCTL source: MySqlAssemblyConsole.exe, 00000002.00000002.431950003.0000000000828000.00000004.00000020.sdmp
Source: Binary string: wscui.pdb source: explorer.exe, 00000012.00000000.417250705.000000000ED20000.00000002.00000001.sdmp

Data Obfuscation:

barindex
Contains functionality to dynamically determine API calls
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00BB25EC LoadLibraryA,GetProcAddress,task,task,task, 27_2_00BB25EC
Uses code obfuscation techniques (call, push, ret)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC68DD push 00000061h; retf 2_2_00BC68DF
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC71EC push edx; iretd 2_2_00BC71ED
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC69D2 push eax; retf 2_2_00BC69D9
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC7AB9 push esp; iretd 2_2_00BC7AB2
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC7AED push esp; iretd 2_2_00BC7AB2
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC7A65 push esp; iretd 2_2_00BC7AB2
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC7A43 push esp; iretd 2_2_00BC7AB2
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BE4D8C push eax; retf 2_2_00BE4D8D
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC6510 push edx; retf FAF5h 2_2_00BC65AF
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BC7D42 push edx; ret 2_2_00BC7D44
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCCEA5 push eax; ret 2_2_00BCCEF8
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCCEFB push eax; ret 2_2_00BCCF62
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BCBE22 push edx; iretd 2_2_00BCBE29
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045DD0D1 push ecx; ret 23_2_045DD0E4
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02747A65 push esp; iretd 23_2_02747AB2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02747A43 push esp; iretd 23_2_02747AB2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274DA32 push esp; retf 23_2_0274DA34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02747AED push esp; iretd 23_2_02747AB2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02747AB9 push esp; iretd 23_2_02747AB2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274DBA4 push es; ret 23_2_0274DBAA
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_027471EC push edx; iretd 23_2_027471ED
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274BE22 push edx; iretd 23_2_0274BE29
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274CEF2 push eax; ret 23_2_0274CEF8
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274CEFB push eax; ret 23_2_0274CF62
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274CEA5 push eax; ret 23_2_0274CEF8
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0274CF5C push eax; ret 23_2_0274CF62
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_02747D42 push edx; ret 23_2_02747D44
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00BB4502 pushfd ; iretd 27_2_00BB4503
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00BB3AEC pushad ; ret 27_2_00BB3AED
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00D08BF9 push ecx; ret 27_2_00D08C0C

Persistence and Installation Behavior:

barindex
Drops PE files
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libffi-7.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libgmodule-2.0-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libimpl3.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libSDL_Pango-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libwinpthread-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\SDL_ttf.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libcairo-gobject-2.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libpangocairo-1.0-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libbrotlidec.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libdatrie-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\INSTALL.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\FAQ.txt Jump to behavior
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File created: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\en\README.txt Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Registry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run SLHH9VSPLX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Registry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run SLHH9VSPLX Jump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Modifies the prolog of user mode functions (user mode inline hooks)
Source: explorer.exe User mode code has changed: module: user32.dll function: PeekMessageA new code: 0x48 0x8B 0xB8 0x89 0x9E 0xEE
Extensive use of GetProcAddress (often used to hide API calls)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00BB58C0 wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress,wglGetProcAddress, 27_2_00BB58C0
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion:

barindex
Tries to detect virtualization through RDTSC time measurements
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe RDTSC instruction interceptor: First address: 0000000000BB98E4 second address: 0000000000BB98EA instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe RDTSC instruction interceptor: First address: 0000000000BB9B4E second address: 0000000000BB9B54 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Windows\SysWOW64\raserver.exe RDTSC instruction interceptor: First address: 00000000027398E4 second address: 00000000027398EA instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Windows\SysWOW64\raserver.exe RDTSC instruction interceptor: First address: 0000000002739B4E second address: 0000000002739B54 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Contains capabilities to detect virtual machines
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe File opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} Jump to behavior
Contains functionality for execution timing, often used to detect debuggers
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB9A80 rdtsc 2_2_00BB9A80
Found dropped PE file which has not been started or loaded
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libffi-7.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libgmodule-2.0-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libSDL_Pango-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libwinpthread-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\SDL_ttf.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libcairo-gobject-2.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libpangocairo-1.0-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libbrotlidec.dll Jump to dropped file
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\libdatrie-1.dll Jump to dropped file
May sleep (evasive loops) to hinder dynamic analysis
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -65000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64888s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64779s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64673s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64561s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64454s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64348s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64238s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -64020s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63871s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63770s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63658s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63551s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63441s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63223s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63108s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -63004s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62894s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62785s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62676s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62567s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62457s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62348s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -62020s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61909s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61800s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61364s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61145s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -61035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60925s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60817s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60703s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60598s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60488s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60378s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60270s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60160s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -60051s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59942s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59832s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59723s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59613s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59504s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59395s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59285s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59176s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -59067s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58957s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58848s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58738s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58629s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58520s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58410s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58301s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58191s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -58082s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57971s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57863s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57754s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57641s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57535s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57425s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57317s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57207s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -57098s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56988s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56879s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56770s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56660s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56551s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56440s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56223s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56113s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -56004s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55889s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55785s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55676s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55567s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55457s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55348s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55238s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -55020s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54910s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54800s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54363s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54145s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -54035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53922s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53813s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53662s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53481s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53379s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53265s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53160s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -53049s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -52887s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -52441s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -52332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -52223s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -52113s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -51884s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -51064s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50957s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50848s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50737s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50629s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50520s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50411s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50301s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50192s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -50082s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49973s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49864s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49753s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49645s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49535s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49426s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49315s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49207s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -49098s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48989s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48879s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48770s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48660s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48551s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48442s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48223s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48113s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -48004s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47895s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47785s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47675s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47567s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47457s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47348s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47238s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47128s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -47019s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46909s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46800s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46363s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46144s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -46035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45926s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45817s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45706s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45598s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45488s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45375s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45270s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45159s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -45051s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44935s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44832s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44723s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44614s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44504s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44393s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44285s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44174s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -44066s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43957s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43848s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43738s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43629s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43520s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43410s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43301s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43191s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -43082s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42972s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42864s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42754s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42642s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42535s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42426s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42317s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42207s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -42098s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41988s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41879s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41770s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41660s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41551s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41442s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41223s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41114s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -41004s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40895s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40785s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40676s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40566s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40457s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40347s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40237s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -40020s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39910s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39797s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39363s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39238s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -39019s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38910s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38801s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38363s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38145s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -38035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37926s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37817s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37707s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37598s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37488s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37379s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37270s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37160s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -37051s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36941s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36832s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36723s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36613s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36504s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36394s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36285s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36176s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -36067s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35957s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35847s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35738s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35629s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35520s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35410s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35253s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35144s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -35035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34923s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34781s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34675s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34565s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34215s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34113s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -34004s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -33886s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -33442s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -33332s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -33190s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32859s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32689s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32473s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32364s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32145s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -32035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31925s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31816s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31707s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31597s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31488s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31379s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31269s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31160s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -31051s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30941s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30832s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30723s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30613s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30504s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30395s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30285s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30176s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5448 Thread sleep time: -30066s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -65000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64885s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64776s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64662s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64510s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64400s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64291s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64182s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -64072s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63962s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63853s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63744s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63635s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63525s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63416s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63306s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63197s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -63088s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62979s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62869s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62760s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62651s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62541s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62431s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62322s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62213s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -62104s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61994s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61885s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61775s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61664s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61556s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61448s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61338s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61229s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61119s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -61010s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60901s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60791s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60682s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60572s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60463s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60353s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60244s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60135s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -60026s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59916s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59794s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59594s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59478s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59362s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59228s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59118s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -59010s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -58900s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -58504s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -58399s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -58290s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -57032s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56884s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56756s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56643s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56541s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56432s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56322s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56213s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -56104s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55994s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55885s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55775s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55666s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55557s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55448s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55337s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55229s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55119s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -55010s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54900s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54791s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54682s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54572s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54463s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54354s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54244s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54133s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -54021s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53916s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53807s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53697s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53588s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53479s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53369s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53260s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53151s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -53041s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52932s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52822s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52713s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52603s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52494s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 5668 Thread sleep time: -52385s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -65000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64894s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64785s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64675s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64566s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64457s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64345s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64238s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64129s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -64019s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63910s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63800s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63691s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63582s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63472s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63360s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63254s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63144s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -63035s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62926s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62816s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62707s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62597s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62488s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62379s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62269s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62160s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -62050s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -61941s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -61831s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe TID: 3556 Thread sleep time: -61722s >= -30000s Jump to behavior
Sample execution stops while process was sleeping (likely an evasion)
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_0040646B FindFirstFileA,FindClose, 0_2_0040646B
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_004027A1 FindFirstFileA, 0_2_004027A1
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, 0_2_004058BF
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 65000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64888 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64779 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64673 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64561 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64454 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64348 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64238 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64020 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63871 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63770 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63658 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63551 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63441 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63223 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63108 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63004 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62894 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62785 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62676 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62567 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62457 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62348 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62020 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61909 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61800 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61364 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61145 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60925 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60817 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60703 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60598 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60488 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60378 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60270 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60160 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60051 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59942 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59832 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59723 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59613 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59504 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59395 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59285 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59176 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59067 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58957 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58848 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58738 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58629 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58520 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58410 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58301 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58191 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58082 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57971 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57863 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57754 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57641 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57535 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57425 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57317 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57207 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57098 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56988 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56879 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56770 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56660 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56551 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56440 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56223 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56113 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56004 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55889 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55785 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55676 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55567 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55457 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55348 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55238 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55020 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54910 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54800 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54363 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54145 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53922 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53813 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53662 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53481 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53379 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53265 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53160 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53049 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52887 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52441 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52223 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52113 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 51884 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 51064 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50957 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50848 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50737 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50629 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50520 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50411 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50301 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50192 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 50082 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49973 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49864 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49753 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49645 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49535 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49426 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49315 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49207 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 49098 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48989 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48879 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48770 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48660 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48551 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48442 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48223 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48113 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 48004 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47895 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47785 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47675 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47567 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47457 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47348 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47238 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47128 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 47019 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46909 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46800 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46363 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46144 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 46035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45926 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45817 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45706 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45598 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45488 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45375 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45270 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45159 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 45051 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44935 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44832 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44723 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44614 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44504 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44393 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44285 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44174 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 44066 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43957 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43848 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43738 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43629 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43520 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43410 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43301 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43191 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 43082 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42972 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42864 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42754 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42642 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42535 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42426 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42317 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42207 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 42098 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41988 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41879 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41770 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41660 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41551 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41442 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41223 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41114 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 41004 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40895 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40785 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40676 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40566 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40457 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40347 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40237 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 40020 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39910 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39797 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39363 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39238 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 39019 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38910 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38801 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38363 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38145 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 38035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37926 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37817 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37707 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37598 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37488 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37379 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37270 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37160 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 37051 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36941 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36832 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36723 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36613 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36504 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36394 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36285 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36176 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 36067 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35957 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35847 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35738 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35629 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35520 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35410 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35253 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35144 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 35035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34923 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34781 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34675 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34565 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34215 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34113 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 34004 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 33886 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 33442 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 33332 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 33190 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32859 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32689 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32473 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32364 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32145 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 32035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31925 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31816 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31707 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31597 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31488 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31379 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31269 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31160 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 31051 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30941 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30832 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30723 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30613 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30504 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30395 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30285 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30176 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 30066 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 65000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64885 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64776 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64662 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64510 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64400 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64291 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64182 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64072 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63962 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63853 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63744 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63635 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63525 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63416 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63306 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63197 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63088 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62979 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62869 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62760 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62651 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62541 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62431 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62322 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62213 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62104 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61994 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61885 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61775 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61664 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61556 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61448 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61338 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61229 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61119 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61010 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60901 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60791 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60682 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60572 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60463 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60353 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60244 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60135 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 60026 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59916 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59794 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59594 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59478 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59362 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59228 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59118 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 59010 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58900 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58504 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58399 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 58290 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 57032 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56884 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56756 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56643 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56541 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56432 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56322 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56213 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 56104 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55994 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55885 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55775 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55666 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55557 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55448 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55337 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55229 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55119 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 55010 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54900 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54791 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54682 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54572 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54463 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54354 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54244 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54133 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 54021 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53916 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53807 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53697 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53588 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53479 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53369 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53260 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53151 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 53041 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52932 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52822 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52713 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52603 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52494 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 52385 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 65000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64894 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64785 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64675 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64566 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64457 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64345 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64238 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64129 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 64019 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63910 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63800 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63691 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63582 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63472 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63360 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63254 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63144 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 63035 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62926 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62816 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62707 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62597 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62488 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62379 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62269 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62160 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 62050 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61941 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61831 Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread delayed: delay time: 61722 Jump to behavior
Source: explorer.exe, 00000012.00000000.412531453.000000000891C000.00000004.00000001.sdmp Binary or memory string: VMware SATA CD00dRom0
Source: explorer.exe, 00000012.00000000.412664360.00000000089B5000.00000004.00000001.sdmp Binary or memory string: Prod_VMware_SATA?6
Source: explorer.exe, 00000012.00000002.509467416.0000000003710000.00000004.00000001.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: explorer.exe, 00000012.00000000.411602569.0000000008270000.00000002.00000001.sdmp Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: explorer.exe, 00000012.00000000.392841431.00000000011B3000.00000004.00000020.sdmp Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000tft\0
Source: explorer.exe, 00000012.00000000.412664360.00000000089B5000.00000004.00000001.sdmp Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000%
Source: explorer.exe, 00000012.00000000.411602569.0000000008270000.00000002.00000001.sdmp Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: explorer.exe, 00000012.00000002.515746081.00000000053D7000.00000004.00000001.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}>'R\"
Source: explorer.exe, 00000012.00000000.411602569.0000000008270000.00000002.00000001.sdmp Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: explorer.exe, 00000012.00000000.412664360.00000000089B5000.00000004.00000001.sdmp Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&0000002
Source: explorer.exe, 00000012.00000002.515884693.00000000054CA000.00000004.00000001.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: explorer.exe, 00000012.00000000.411602569.0000000008270000.00000002.00000001.sdmp Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service.
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging:

barindex
Checks if the current process is being debugged
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process queried: DebugPort Jump to behavior
Contains functionality for execution timing, often used to detect debuggers
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00BB9A80 rdtsc 2_2_00BB9A80
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C9840 NtDelayExecution,LdrInitializeThunk, 23_2_045C9840
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00CB7823 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00CB7823
Contains functionality to dynamically determine API calls
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00BB25EC LoadLibraryA,GetProcAddress,task,task,task, 27_2_00BB25EC
Contains functionality to read the PEB
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A0050 mov eax, dword ptr fs:[00000030h] 23_2_045A0050
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A0050 mov eax, dword ptr fs:[00000030h] 23_2_045A0050
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA44B mov eax, dword ptr fs:[00000030h] 23_2_045BA44B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04651074 mov eax, dword ptr fs:[00000030h] 23_2_04651074
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04642073 mov eax, dword ptr fs:[00000030h] 23_2_04642073
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461C450 mov eax, dword ptr fs:[00000030h] 23_2_0461C450
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461C450 mov eax, dword ptr fs:[00000030h] 23_2_0461C450
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A746D mov eax, dword ptr fs:[00000030h] 23_2_045A746D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641C06 mov eax, dword ptr fs:[00000030h] 23_2_04641C06
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0465740D mov eax, dword ptr fs:[00000030h] 23_2_0465740D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0465740D mov eax, dword ptr fs:[00000030h] 23_2_0465740D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0465740D mov eax, dword ptr fs:[00000030h] 23_2_0465740D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606C0A mov eax, dword ptr fs:[00000030h] 23_2_04606C0A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606C0A mov eax, dword ptr fs:[00000030h] 23_2_04606C0A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606C0A mov eax, dword ptr fs:[00000030h] 23_2_04606C0A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606C0A mov eax, dword ptr fs:[00000030h] 23_2_04606C0A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04654015 mov eax, dword ptr fs:[00000030h] 23_2_04654015
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04654015 mov eax, dword ptr fs:[00000030h] 23_2_04654015
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459B02A mov eax, dword ptr fs:[00000030h] 23_2_0459B02A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459B02A mov eax, dword ptr fs:[00000030h] 23_2_0459B02A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459B02A mov eax, dword ptr fs:[00000030h] 23_2_0459B02A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459B02A mov eax, dword ptr fs:[00000030h] 23_2_0459B02A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607016 mov eax, dword ptr fs:[00000030h] 23_2_04607016
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607016 mov eax, dword ptr fs:[00000030h] 23_2_04607016
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607016 mov eax, dword ptr fs:[00000030h] 23_2_04607016
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B002D mov eax, dword ptr fs:[00000030h] 23_2_045B002D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B002D mov eax, dword ptr fs:[00000030h] 23_2_045B002D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B002D mov eax, dword ptr fs:[00000030h] 23_2_045B002D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B002D mov eax, dword ptr fs:[00000030h] 23_2_045B002D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B002D mov eax, dword ptr fs:[00000030h] 23_2_045B002D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BBC2C mov eax, dword ptr fs:[00000030h] 23_2_045BBC2C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606CF0 mov eax, dword ptr fs:[00000030h] 23_2_04606CF0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606CF0 mov eax, dword ptr fs:[00000030h] 23_2_04606CF0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606CF0 mov eax, dword ptr fs:[00000030h] 23_2_04606CF0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046414FB mov eax, dword ptr fs:[00000030h] 23_2_046414FB
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov eax, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov ecx, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov eax, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov eax, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov eax, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461B8D0 mov eax, dword ptr fs:[00000030h] 23_2_0461B8D0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658CD6 mov eax, dword ptr fs:[00000030h] 23_2_04658CD6
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045858EC mov eax, dword ptr fs:[00000030h] 23_2_045858EC
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459849B mov eax, dword ptr fs:[00000030h] 23_2_0459849B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589080 mov eax, dword ptr fs:[00000030h] 23_2_04589080
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BF0BF mov ecx, dword ptr fs:[00000030h] 23_2_045BF0BF
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BF0BF mov eax, dword ptr fs:[00000030h] 23_2_045BF0BF
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BF0BF mov eax, dword ptr fs:[00000030h] 23_2_045BF0BF
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04603884 mov eax, dword ptr fs:[00000030h] 23_2_04603884
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04603884 mov eax, dword ptr fs:[00000030h] 23_2_04603884
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C90AF mov eax, dword ptr fs:[00000030h] 23_2_045C90AF
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B20A0 mov eax, dword ptr fs:[00000030h] 23_2_045B20A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A7D50 mov eax, dword ptr fs:[00000030h] 23_2_045A7D50
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AB944 mov eax, dword ptr fs:[00000030h] 23_2_045AB944
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AB944 mov eax, dword ptr fs:[00000030h] 23_2_045AB944
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C3D43 mov eax, dword ptr fs:[00000030h] 23_2_045C3D43
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04603540 mov eax, dword ptr fs:[00000030h] 23_2_04603540
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458B171 mov eax, dword ptr fs:[00000030h] 23_2_0458B171
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458B171 mov eax, dword ptr fs:[00000030h] 23_2_0458B171
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AC577 mov eax, dword ptr fs:[00000030h] 23_2_045AC577
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AC577 mov eax, dword ptr fs:[00000030h] 23_2_045AC577
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458C962 mov eax, dword ptr fs:[00000030h] 23_2_0458C962
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658D34 mov eax, dword ptr fs:[00000030h] 23_2_04658D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0460A537 mov eax, dword ptr fs:[00000030h] 23_2_0460A537
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589100 mov eax, dword ptr fs:[00000030h] 23_2_04589100
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589100 mov eax, dword ptr fs:[00000030h] 23_2_04589100
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589100 mov eax, dword ptr fs:[00000030h] 23_2_04589100
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4D3B mov eax, dword ptr fs:[00000030h] 23_2_045B4D3B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4D3B mov eax, dword ptr fs:[00000030h] 23_2_045B4D3B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4D3B mov eax, dword ptr fs:[00000030h] 23_2_045B4D3B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B513A mov eax, dword ptr fs:[00000030h] 23_2_045B513A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B513A mov eax, dword ptr fs:[00000030h] 23_2_045B513A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458AD30 mov eax, dword ptr fs:[00000030h] 23_2_0458AD30
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04593D34 mov eax, dword ptr fs:[00000030h] 23_2_04593D34
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 mov eax, dword ptr fs:[00000030h] 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 mov eax, dword ptr fs:[00000030h] 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 mov eax, dword ptr fs:[00000030h] 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 mov eax, dword ptr fs:[00000030h] 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A4120 mov ecx, dword ptr fs:[00000030h] 23_2_045A4120
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464FDE2 mov eax, dword ptr fs:[00000030h] 23_2_0464FDE2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464FDE2 mov eax, dword ptr fs:[00000030h] 23_2_0464FDE2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464FDE2 mov eax, dword ptr fs:[00000030h] 23_2_0464FDE2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464FDE2 mov eax, dword ptr fs:[00000030h] 23_2_0464FDE2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046141E8 mov eax, dword ptr fs:[00000030h] 23_2_046141E8
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04638DF1 mov eax, dword ptr fs:[00000030h] 23_2_04638DF1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov eax, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov eax, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov eax, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov ecx, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov eax, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04606DC9 mov eax, dword ptr fs:[00000030h] 23_2_04606DC9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458B1E1 mov eax, dword ptr fs:[00000030h] 23_2_0458B1E1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458B1E1 mov eax, dword ptr fs:[00000030h] 23_2_0458B1E1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458B1E1 mov eax, dword ptr fs:[00000030h] 23_2_0458B1E1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459D5E0 mov eax, dword ptr fs:[00000030h] 23_2_0459D5E0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459D5E0 mov eax, dword ptr fs:[00000030h] 23_2_0459D5E0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BFD9B mov eax, dword ptr fs:[00000030h] 23_2_045BFD9B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BFD9B mov eax, dword ptr fs:[00000030h] 23_2_045BFD9B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046069A6 mov eax, dword ptr fs:[00000030h] 23_2_046069A6
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046505AC mov eax, dword ptr fs:[00000030h] 23_2_046505AC
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046505AC mov eax, dword ptr fs:[00000030h] 23_2_046505AC
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2990 mov eax, dword ptr fs:[00000030h] 23_2_045B2990
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04582D8A mov eax, dword ptr fs:[00000030h] 23_2_04582D8A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04582D8A mov eax, dword ptr fs:[00000030h] 23_2_04582D8A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04582D8A mov eax, dword ptr fs:[00000030h] 23_2_04582D8A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04582D8A mov eax, dword ptr fs:[00000030h] 23_2_04582D8A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04582D8A mov eax, dword ptr fs:[00000030h] 23_2_04582D8A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AC182 mov eax, dword ptr fs:[00000030h] 23_2_045AC182
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2581 mov eax, dword ptr fs:[00000030h] 23_2_045B2581
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2581 mov eax, dword ptr fs:[00000030h] 23_2_045B2581
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2581 mov eax, dword ptr fs:[00000030h] 23_2_045B2581
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2581 mov eax, dword ptr fs:[00000030h] 23_2_045B2581
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA185 mov eax, dword ptr fs:[00000030h] 23_2_045BA185
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046051BE mov eax, dword ptr fs:[00000030h] 23_2_046051BE
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046051BE mov eax, dword ptr fs:[00000030h] 23_2_046051BE
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046051BE mov eax, dword ptr fs:[00000030h] 23_2_046051BE
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046051BE mov eax, dword ptr fs:[00000030h] 23_2_046051BE
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B1DB5 mov eax, dword ptr fs:[00000030h] 23_2_045B1DB5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B1DB5 mov eax, dword ptr fs:[00000030h] 23_2_045B1DB5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B1DB5 mov eax, dword ptr fs:[00000030h] 23_2_045B1DB5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B35A1 mov eax, dword ptr fs:[00000030h] 23_2_045B35A1
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B61A0 mov eax, dword ptr fs:[00000030h] 23_2_045B61A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B61A0 mov eax, dword ptr fs:[00000030h] 23_2_045B61A0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0463B260 mov eax, dword ptr fs:[00000030h] 23_2_0463B260
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0463B260 mov eax, dword ptr fs:[00000030h] 23_2_0463B260
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658A62 mov eax, dword ptr fs:[00000030h] 23_2_04658A62
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589240 mov eax, dword ptr fs:[00000030h] 23_2_04589240
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589240 mov eax, dword ptr fs:[00000030h] 23_2_04589240
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589240 mov eax, dword ptr fs:[00000030h] 23_2_04589240
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04589240 mov eax, dword ptr fs:[00000030h] 23_2_04589240
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04597E41 mov eax, dword ptr fs:[00000030h] 23_2_04597E41
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C927A mov eax, dword ptr fs:[00000030h] 23_2_045C927A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AAE73 mov eax, dword ptr fs:[00000030h] 23_2_045AAE73
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AAE73 mov eax, dword ptr fs:[00000030h] 23_2_045AAE73
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AAE73 mov eax, dword ptr fs:[00000030h] 23_2_045AAE73
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AAE73 mov eax, dword ptr fs:[00000030h] 23_2_045AAE73
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AAE73 mov eax, dword ptr fs:[00000030h] 23_2_045AAE73
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464EA55 mov eax, dword ptr fs:[00000030h] 23_2_0464EA55
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459766D mov eax, dword ptr fs:[00000030h] 23_2_0459766D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04614257 mov eax, dword ptr fs:[00000030h] 23_2_04614257
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045A3A1C mov eax, dword ptr fs:[00000030h] 23_2_045A3A1C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA61C mov eax, dword ptr fs:[00000030h] 23_2_045BA61C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA61C mov eax, dword ptr fs:[00000030h] 23_2_045BA61C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04585210 mov eax, dword ptr fs:[00000030h] 23_2_04585210
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04585210 mov ecx, dword ptr fs:[00000030h] 23_2_04585210
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04585210 mov eax, dword ptr fs:[00000030h] 23_2_04585210
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04585210 mov eax, dword ptr fs:[00000030h] 23_2_04585210
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458AA16 mov eax, dword ptr fs:[00000030h] 23_2_0458AA16
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458AA16 mov eax, dword ptr fs:[00000030h] 23_2_0458AA16
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04598A0A mov eax, dword ptr fs:[00000030h] 23_2_04598A0A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458C600 mov eax, dword ptr fs:[00000030h] 23_2_0458C600
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458C600 mov eax, dword ptr fs:[00000030h] 23_2_0458C600
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458C600 mov eax, dword ptr fs:[00000030h] 23_2_0458C600
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B8E00 mov eax, dword ptr fs:[00000030h] 23_2_045B8E00
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0463FE3F mov eax, dword ptr fs:[00000030h] 23_2_0463FE3F
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04641608 mov eax, dword ptr fs:[00000030h] 23_2_04641608
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C4A2C mov eax, dword ptr fs:[00000030h] 23_2_045C4A2C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C4A2C mov eax, dword ptr fs:[00000030h] 23_2_045C4A2C
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458E620 mov eax, dword ptr fs:[00000030h] 23_2_0458E620
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2ACB mov eax, dword ptr fs:[00000030h] 23_2_045B2ACB
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B36CC mov eax, dword ptr fs:[00000030h] 23_2_045B36CC
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C8EC7 mov eax, dword ptr fs:[00000030h] 23_2_045C8EC7
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0463FEC0 mov eax, dword ptr fs:[00000030h] 23_2_0463FEC0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658ED6 mov eax, dword ptr fs:[00000030h] 23_2_04658ED6
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B16E0 mov ecx, dword ptr fs:[00000030h] 23_2_045B16E0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045976E2 mov eax, dword ptr fs:[00000030h] 23_2_045976E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2AE4 mov eax, dword ptr fs:[00000030h] 23_2_045B2AE4
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04650EA5 mov eax, dword ptr fs:[00000030h] 23_2_04650EA5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04650EA5 mov eax, dword ptr fs:[00000030h] 23_2_04650EA5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04650EA5 mov eax, dword ptr fs:[00000030h] 23_2_04650EA5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046046A7 mov eax, dword ptr fs:[00000030h] 23_2_046046A7
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BD294 mov eax, dword ptr fs:[00000030h] 23_2_045BD294
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BD294 mov eax, dword ptr fs:[00000030h] 23_2_045BD294
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461FE87 mov eax, dword ptr fs:[00000030h] 23_2_0461FE87
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459AAB0 mov eax, dword ptr fs:[00000030h] 23_2_0459AAB0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459AAB0 mov eax, dword ptr fs:[00000030h] 23_2_0459AAB0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BFAB0 mov eax, dword ptr fs:[00000030h] 23_2_045BFAB0
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045852A5 mov eax, dword ptr fs:[00000030h] 23_2_045852A5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045852A5 mov eax, dword ptr fs:[00000030h] 23_2_045852A5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045852A5 mov eax, dword ptr fs:[00000030h] 23_2_045852A5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045852A5 mov eax, dword ptr fs:[00000030h] 23_2_045852A5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045852A5 mov eax, dword ptr fs:[00000030h] 23_2_045852A5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458F358 mov eax, dword ptr fs:[00000030h] 23_2_0458F358
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658F6A mov eax, dword ptr fs:[00000030h] 23_2_04658F6A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458DB40 mov eax, dword ptr fs:[00000030h] 23_2_0458DB40
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459EF40 mov eax, dword ptr fs:[00000030h] 23_2_0459EF40
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B3B7A mov eax, dword ptr fs:[00000030h] 23_2_045B3B7A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B3B7A mov eax, dword ptr fs:[00000030h] 23_2_045B3B7A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0458DB60 mov ecx, dword ptr fs:[00000030h] 23_2_0458DB60
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0459FF60 mov eax, dword ptr fs:[00000030h] 23_2_0459FF60
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04658B58 mov eax, dword ptr fs:[00000030h] 23_2_04658B58
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045AF716 mov eax, dword ptr fs:[00000030h] 23_2_045AF716
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA70E mov eax, dword ptr fs:[00000030h] 23_2_045BA70E
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BA70E mov eax, dword ptr fs:[00000030h] 23_2_045BA70E
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0465070D mov eax, dword ptr fs:[00000030h] 23_2_0465070D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0465070D mov eax, dword ptr fs:[00000030h] 23_2_0465070D
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BE730 mov eax, dword ptr fs:[00000030h] 23_2_045BE730
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461FF10 mov eax, dword ptr fs:[00000030h] 23_2_0461FF10
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0461FF10 mov eax, dword ptr fs:[00000030h] 23_2_0461FF10
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04584F2E mov eax, dword ptr fs:[00000030h] 23_2_04584F2E
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04584F2E mov eax, dword ptr fs:[00000030h] 23_2_04584F2E
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464131B mov eax, dword ptr fs:[00000030h] 23_2_0464131B
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045C37F5 mov eax, dword ptr fs:[00000030h] 23_2_045C37F5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046053CA mov eax, dword ptr fs:[00000030h] 23_2_046053CA
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_046053CA mov eax, dword ptr fs:[00000030h] 23_2_046053CA
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045ADBE9 mov eax, dword ptr fs:[00000030h] 23_2_045ADBE9
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B03E2 mov eax, dword ptr fs:[00000030h] 23_2_045B03E2
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04655BA5 mov eax, dword ptr fs:[00000030h] 23_2_04655BA5
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045BB390 mov eax, dword ptr fs:[00000030h] 23_2_045BB390
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B2397 mov eax, dword ptr fs:[00000030h] 23_2_045B2397
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04598794 mov eax, dword ptr fs:[00000030h] 23_2_04598794
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04591B8F mov eax, dword ptr fs:[00000030h] 23_2_04591B8F
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04591B8F mov eax, dword ptr fs:[00000030h] 23_2_04591B8F
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0463D380 mov ecx, dword ptr fs:[00000030h] 23_2_0463D380
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_0464138A mov eax, dword ptr fs:[00000030h] 23_2_0464138A
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607794 mov eax, dword ptr fs:[00000030h] 23_2_04607794
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607794 mov eax, dword ptr fs:[00000030h] 23_2_04607794
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_04607794 mov eax, dword ptr fs:[00000030h] 23_2_04607794
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4BAD mov eax, dword ptr fs:[00000030h] 23_2_045B4BAD
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4BAD mov eax, dword ptr fs:[00000030h] 23_2_045B4BAD
Source: C:\Windows\SysWOW64\raserver.exe Code function: 23_2_045B4BAD mov eax, dword ptr fs:[00000030h] 23_2_045B4BAD
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E04FF14 mov eax, dword ptr fs:[00000030h] 28_2_6E04FF14
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E049D71 mov eax, dword ptr fs:[00000030h] 28_2_6E049D71
Enables debug privileges
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00CB7823 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00CB7823
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00CA813B SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00CA813B
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00CB7823 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 27_2_00CB7823
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 27_2_00CA813B SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 27_2_00CA813B
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E0467BD SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 28_2_6E0467BD
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E0475D2 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 28_2_6E0475D2
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E04CAF9 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 28_2_6E04CAF9

HIPS / PFW / Operating System Protection Evasion:

barindex
Maps a DLL or memory area into another process
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Section loaded: unknown target: C:\Windows\SysWOW64\raserver.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Section loaded: unknown target: C:\Windows\SysWOW64\raserver.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write Jump to behavior
Modifies the context of a thread in another process (thread injection)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread register set: target process: 3472 Jump to behavior
Source: C:\Windows\SysWOW64\raserver.exe Thread register set: target process: 3472 Jump to behavior
Queues an APC in another process (thread injection)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Thread APC queued: target process: C:\Windows\explorer.exe Jump to behavior
Sample uses process hollowing technique
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Section unmapped: C:\Windows\SysWOW64\raserver.exe base address: 100000 Jump to behavior
Creates a process in suspended mode (likely to inject code)
Source: C:\Windows\SysWOW64\raserver.exe Process created: C:\Windows\SysWOW64\cmd.exe /c copy 'C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data' 'C:\Users\user\AppData\Local\Temp\DB1' /V Jump to behavior
Source: explorer.exe, 00000012.00000002.504552070.0000000001640000.00000002.00000001.sdmp, raserver.exe, 00000017.00000002.505933519.0000000002E10000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506006329.0000000001170000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.505673751.0000000000DE0000.00000002.00000001.sdmp Binary or memory string: Shell_TrayWnd
Source: explorer.exe, 00000012.00000002.504552070.0000000001640000.00000002.00000001.sdmp, raserver.exe, 00000017.00000002.505933519.0000000002E10000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506006329.0000000001170000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.505673751.0000000000DE0000.00000002.00000001.sdmp Binary or memory string: Progman
Source: explorer.exe, 00000012.00000002.504552070.0000000001640000.00000002.00000001.sdmp, raserver.exe, 00000017.00000002.505933519.0000000002E10000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506006329.0000000001170000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.505673751.0000000000DE0000.00000002.00000001.sdmp Binary or memory string: SProgram Managerl
Source: explorer.exe, 00000012.00000000.392773721.0000000001128000.00000004.00000020.sdmp Binary or memory string: ProgmanOMEa
Source: explorer.exe, 00000012.00000002.504552070.0000000001640000.00000002.00000001.sdmp, raserver.exe, 00000017.00000002.505933519.0000000002E10000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506006329.0000000001170000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.505673751.0000000000DE0000.00000002.00000001.sdmp Binary or memory string: Shell_TrayWnd,
Source: explorer.exe, 00000012.00000002.504552070.0000000001640000.00000002.00000001.sdmp, raserver.exe, 00000017.00000002.505933519.0000000002E10000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001B.00000002.506006329.0000000001170000.00000002.00000001.sdmp, MySqlAssemblyConsole.exe, 0000001C.00000002.505673751.0000000000DE0000.00000002.00000001.sdmp Binary or memory string: Progmanlock

Language, Device and Operating System Detection:

barindex
Contains functionality to query CPU information (cpuid)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 28_2_6E046FF1 cpuid 28_2_6E046FF1
Contains functionality to query locales information (e.g. system language)
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: GetLocaleInfoW, 28_2_6E051497
Source: C:\Users\user\AppData\Roaming\MySqlConsoleComponents\MySqlAssemblyConsole.exe Code function: 2_2_00CA8986 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 2_2_00CA8986
Source: C:\Users\user\Desktop\PURCHASE ORDER.exe Code function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_00403348

Stealing of Sensitive Information:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE
Tries to harvest and steal browser information (history, passwords, etc)
Source: C:\Windows\SysWOW64\raserver.exe File opened: C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login Data Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Tries to steal Mail credentials (via file access)
Source: C:\Windows\SysWOW64\raserver.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ Jump to behavior

Remote Access Functionality:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.431726955.00000000005D0000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.431752828.0000000000600000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.503999453.00000000004A0000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432758571.00000000027EC000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000017.00000002.505688448.0000000002730000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.432137722.0000000000BB1000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 2.2.MySqlAssemblyConsole.exe.bb0000.2.unpack, type: UNPACKEDPE
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 385280 Sample: PURCHASE ORDER.com Startdate: 12/04/2021 Architecture: WINDOWS Score: 100 46 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->46 48 Found malware configuration 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 7 other signatures 2->52 10 PURCHASE ORDER.exe 179 2->10         started        process3 file4 36 C:\Users\user\...\MySqlAssemblyConsole.exe, PE32 10->36 dropped 38 C:\Users\user\AppData\...\libwinpthread-1.dll, PE32+ 10->38 dropped 40 C:\Users\user\...\libpangocairo-1.0-0.dll, PE32+ 10->40 dropped 42 8 other files (none is malicious) 10->42 dropped 13 MySqlAssemblyConsole.exe 10->13         started        process5 signatures6 64 Machine Learning detection for dropped file 13->64 66 Modifies the context of a thread in another process (thread injection) 13->66 68 Maps a DLL or memory area into another process 13->68 70 3 other signatures 13->70 16 explorer.exe 3 13->16 injected process7 process8 18 raserver.exe 1 18 16->18         started        22 MySqlAssemblyConsole.exe 16->22         started        24 MySqlAssemblyConsole.exe 16->24         started        file9 32 C:\Users\user\AppData\...\886logrv.ini, data 18->32 dropped 34 C:\Users\user\AppData\...\886logri.ini, data 18->34 dropped 54 Detected FormBook malware 18->54 56 Tries to steal Mail credentials (via file access) 18->56 58 Tries to harvest and steal browser information (history, passwords, etc) 18->58 60 3 other signatures 18->60 26 cmd.exe 2 18->26         started        signatures10 process11 file12 44 C:\Users\user\AppData\Local\Temp\DB1, SQLite 26->44 dropped 62 Tries to harvest and steal browser information (history, passwords, etc) 26->62 30 conhost.exe 26->30         started        signatures13 process14
No contacted IP infos

Contacted URLs

Name Malicious Antivirus Detection Reputation
www.hollandhousedesigns.design/vns/ true
  • 5%, Virustotal, Browse
  • Avira URL Cloud: safe
low