Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040CC56 __EH_prolog,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,wsprintfA,CryptUnprotectData, | 1_2_0040CC56 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040ED62 __EH_prolog,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,wsprintfA,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, | 1_2_0040ED62 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040D35A __EH_prolog,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,wsprintfA,CryptUnprotectData,LocalFree, | 1_2_0040D35A |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00427411 CryptAcquireContextA,CryptCreateHash,lstrlenW,CryptHashData,CryptGetHashParam,wsprintfW,lstrcatW,wsprintfW,lstrcatW,CryptDestroyHash,CryptReleaseContext,lstrlenW,CryptUnprotectData,LocalFree, | 1_2_00427411 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004275E4 lstrlenW,lstrlenW,lstrlenW,CredEnumerateW,CryptUnprotectData,LocalFree,CredFree, | 1_2_004275E4 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040DDA5 __EH_prolog,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,wsprintfA,CryptUnprotectData,LocalFree,CryptUnprotectData, | 1_2_0040DDA5 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040C07D __EH_prolog,BCryptOpenAlgorithmProvider,BCryptSetProperty,BCryptGenerateSymmetricKey,LocalAlloc,BCryptDecrypt,BCryptCloseAlgorithmProvider,BCryptDestroyKey, | 1_2_0040C07D |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041E578 __EH_prolog,_strlen,CryptStringToBinaryA,PK11_GetInternalKeySlot,PK11_Authenticate,PK11SDR_Decrypt,PK11_FreeSlot, | 1_2_0041E578 |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: freebl3.dll.1.dr |
Source: | Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: api-ms-win-crt-locale-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\gfx\angle\targets\libEGL\libEGL.pdb source: libEGL.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libprldap\prldap60.pdb source: prldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: api-ms-win-crt-runtime-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\ia2\IA2Marshal.pdb source: IA2Marshal.dll.1.dr |
Source: | Binary string: C:\coselu88\cez-yizuyine80_zesudu_peyihubitigufajuzad doseka.pdbpo.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss3.pdb source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: api-ms-win-core-file-l1-2-0.dll.1.dr |
Source: | Binary string: ucrtbase.pdb source: ucrtbase.dll.1.dr |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: api-ms-win-core-memory-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: api-ms-win-core-sysinfo-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldap\ldap60.pdb source: ldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: api-ms-win-crt-filesystem-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: api-ms-win-crt-stdio-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: api-ms-win-core-heap-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-util-l1-1-0.pdb source: api-ms-win-core-util-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-synch-l1-1-0.pdb source: api-ms-win-core-synch-l1-1-0.dll.1.dr |
Source: | Binary string: vcruntime140.i386.pdbGCTL source: vcruntime140.dll.1.dr |
Source: | Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: api-ms-win-crt-environment-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: softokn3.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\ckfw\builtins\builtins_nssckbi\nssckbi.pdb source: nssckbi.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\mozglue\build\mozglue.pdb22! source: 7SlKt2Puui.exe, 00000001.00000002.698110075.000000006D469000.00000002.00020000.sdmp, mozglue.dll.1.dr |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: api-ms-win-core-processthreads-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: freebl3.dll.1.dr |
Source: | Binary string: C:\coselu88\cez-yizuyine80_zesudu_peyihubitigufajuzad doseka.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: api-ms-win-crt-private-l1-1-0.pdb source: api-ms-win-crt-private-l1-1-0.dll.1.dr |
Source: | Binary string: po.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: api-ms-win-crt-convert-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\ipc\win\handler\AccessibleHandler.pdb source: AccessibleHandler.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb-- source: nssdbm3.dll.1.dr |
Source: | Binary string: msvcp140.i386.pdb source: msvcp140.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\mailnews\mapi\mapihook\build\MapiProxy.pdb source: MapiProxy_InUse.dll.1.dr |
Source: | Binary string: ucrtbase.pdbUGP source: ucrtbase.dll.1.dr |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldap\ldap60.pdbUU source: ldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-time-l1-1-0.pdb source: api-ms-win-crt-time-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\ckfw\builtins\builtins_nssckbi\nssckbi.pdb66 source: nssckbi.dll.1.dr |
Source: | Binary string: api-ms-win-core-handle-l1-1-0.pdb source: api-ms-win-core-handle-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-synch-l1-2-0.pdb source: api-ms-win-core-synch-l1-2-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: softokn3.dll.1.dr |
Source: | Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: api-ms-win-core-processenvironment-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\ia2\IA2Marshal.pdb<< source: IA2Marshal.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\mozglue\build\mozglue.pdb source: 7SlKt2Puui.exe, 00000001.00000002.698110075.000000006D469000.00000002.00020000.sdmp, mozglue.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\toolkit\library\dummydll\qipcap.pdb source: qipcap.dll.1.dr |
Source: | Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: api-ms-win-crt-conio-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-localization-l1-2-0.pdb source: api-ms-win-core-localization-l1-2-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-math-l1-1-0.pdb source: api-ms-win-crt-math-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: api-ms-win-core-processthreads-l1-1-1.dll.1.dr |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: api-ms-win-core-namedpipe-l1-1-0.dll.1.dr |
Source: | Binary string: vcruntime140.i386.pdb source: vcruntime140.dll.1.dr |
Source: | Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: api-ms-win-crt-multibyte-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: api-ms-win-crt-utility-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\mailnews\mapi\mapiDLL\mozMapi32.pdb source: mozMapi32.dll.1.dr |
Source: | Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: api-ms-win-core-rtlsupport-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: api-ms-win-core-timezone-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-string-l1-1-0.pdb source: api-ms-win-core-string-l1-1-0.dll.1.dr |
Source: | Binary string: msvcp140.i386.pdbGCTL source: msvcp140.dll.1.dr |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: api-ms-win-core-file-l2-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-process-l1-1-0.pdb source: api-ms-win-crt-process-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: api-ms-win-core-libraryloader-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldif\ldif60.pdb source: ldif60.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\config\external\lgpllibs\lgpllibs.pdb source: lgpllibs.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\msaa\AccessibleMarshal.pdb source: AccessibleMarshal.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb source: nssdbm3.dll.1.dr |
Source: | Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: api-ms-win-core-interlocked-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\toolkit\crashreporter\injector\breakpadinjector.pdb source: breakpadinjector.dll.1.dr |
Source: | Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: api-ms-win-crt-heap-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-string-l1-1-0.pdb source: api-ms-win-crt-string-l1-1-0.dll.1.dr |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\html\ | Jump to behavior |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\_locales\ | Jump to behavior |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\ | Jump to behavior |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\ | Jump to behavior |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\_locales\bg\ | Jump to behavior |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\css\ | Jump to behavior |
Source: softokn3.dll.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://cps.chambersign.org/cps/chambersignroot.html0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.chambersign.org/chambersignroot.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.chambersign.org/chambersroot.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.securetrust.com/SGCA.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.securetrust.com/STCA.crl0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: softokn3.dll.1.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: softokn3.dll.1.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://fedir.comsign.co.il/crl/ComSignCA.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://ocsp.accv.es0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ocsp.digicert.com0N |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://policy.camerfirma.com0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://repository.swisssign.com/0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: softokn3.dll.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.accv.es/legislacion_c.htm0U |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.accv.es00 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.cert.fnmt.es/dpcs/0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.certicamara.com/dpc/0Z |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.certplus.com/CRL/class2.crl0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.chambersign.org1 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.firmaprofesional.com/cps0 |
Source: mozglue.dll.1.dr | String found in binary or memory: http://www.mozilla.com/en-US/blocklist/ |
Source: softokn3.dll.1.dr | String found in binary or memory: http://www.mozilla.com0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.pkioverheid.nl/policies/root-policy-G20 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.quovadis.bm0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.quovadisglobal.com/cps0 |
Source: sqlite3.dll.1.dr | String found in binary or memory: http://www.sqlite.org/copyright.html. |
Source: nssckbi.dll.1.dr | String found in binary or memory: http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: 7SlKt2Puui.exe, 00000001.00000003.686368240.0000000000AAC000.00000004.00000001.sdmp | String found in binary or memory: https://birdmilk.top//l/f/uDxHDnkBuI_ccNKogidJ/b0a4288ab8cefd834adcc7f60dc85cae472bc38cusM |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: nssckbi.dll.1.dr | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: nssckbi.dll.1.dr | String found in binary or memory: https://repository.luxtrust.lu0 |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: 7SlKt2Puui.exe, 00000001.00000003.680986715.0000000000AA8000.00000004.00000001.sdmp, 7SlKt2Puui.exe, 00000001.00000003.681029690.000000004C88D000.00000004.00000001.sdmp | String found in binary or memory: https://support.google.com/chrome/?p=plugin_flash |
Source: 7SlKt2Puui.exe, 00000001.00000003.680986715.0000000000AA8000.00000004.00000001.sdmp, 7SlKt2Puui.exe, 00000001.00000003.681029690.000000004C88D000.00000004.00000001.sdmp | String found in binary or memory: https://support.google.com/chrome/answer/6258784 |
Source: nssckbi.dll.1.dr | String found in binary or memory: https://www.catcert.net/verarrel |
Source: nssckbi.dll.1.dr | String found in binary or memory: https://www.catcert.net/verarrel05 |
Source: softokn3.dll.1.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: 1xVPfvJcrg.1.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004340EE | 1_2_004340EE |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0043454A | 1_2_0043454A |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040C67C | 1_2_0040C67C |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041E71E | 1_2_0041E71E |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040CC56 | 1_2_0040CC56 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040ED62 | 1_2_0040ED62 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00432F99 | 1_2_00432F99 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0043AFB9 | 1_2_0043AFB9 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040D35A | 1_2_0040D35A |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041D384 | 1_2_0041D384 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00429796 | 1_2_00429796 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004277AD | 1_2_004277AD |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041DD64 | 1_2_0041DD64 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0040DDA5 | 1_2_0040DDA5 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004400A5 | 1_2_004400A5 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0044614A | 1_2_0044614A |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00458109 | 1_2_00458109 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00448112 | 1_2_00448112 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041C274 | 1_2_0041C274 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00458229 | 1_2_00458229 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004282DB | 1_2_004282DB |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00420358 | 1_2_00420358 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00440360 | 1_2_00440360 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0043A467 | 1_2_0043A467 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004164BE | 1_2_004164BE |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004149DE | 1_2_004149DE |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_004869E8 | 1_2_004869E8 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_00440A90 | 1_2_00440A90 |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: 7SlKt2Puui.exe, 00000001.00000002.693335306.00000000008E0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamenlsbres.dllj% vs 7SlKt2Puui.exe |
Source: 7SlKt2Puui.exe, 00000001.00000002.697270839.000000004BAB0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenameKernelbase.dll.muij% vs 7SlKt2Puui.exe |
Source: 7SlKt2Puui.exe, 00000001.00000002.698063835.000000004C905000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameapisetstubj% vs 7SlKt2Puui.exe |
Source: 7SlKt2Puui.exe, 00000001.00000002.698132773.000000006D472000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenamemozglue.dll8 vs 7SlKt2Puui.exe |
Source: 7SlKt2Puui.exe, 00000001.00000002.698642427.000000006D5AB000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenamenss3.dll8 vs 7SlKt2Puui.exe |
Source: 7SlKt2Puui.exe, 00000001.00000002.693372133.00000000008F0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamenlsbres.dll.muij% vs 7SlKt2Puui.exe |
Source: softokn3.dll.1.dr | Binary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, sqlite3.dll.1.dr | Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q); |
Source: softokn3.dll.1.dr | Binary or memory string: SELECT ALL %s FROM %s WHERE id=$ID; |
Source: softokn3.dll.1.dr | Binary or memory string: SELECT ALL * FROM %s LIMIT 0; |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, sqlite3.dll.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);docid INTEGER PRIMARY KEY%z, 'c%d%q'%z, langidCREATE TABLE %Q.'%q_content'(%s)CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);< |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, sqlite3.dll.1.dr | Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, sqlite3.dll.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx)); |
Source: softokn3.dll.1.dr | Binary or memory string: UPDATE %s SET %s WHERE id=$ID; |
Source: softokn3.dll.1.dr | Binary or memory string: SELECT ALL * FROM metaData WHERE id=$ID; |
Source: softokn3.dll.1.dr | Binary or memory string: SELECT ALL id FROM %s WHERE %s; |
Source: softokn3.dll.1.dr | Binary or memory string: SELECT ALL id FROM %s; |
Source: softokn3.dll.1.dr | Binary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1); |
Source: sqlite3.dll.1.dr | Binary or memory string: UPDATE %Q.%s SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger'); |
Source: softokn3.dll.1.dr | Binary or memory string: INSERT INTO %s (id%s) VALUES($ID%s); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s; |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s; |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, sqlite3.dll.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: CREATE TABLE xx( name TEXT, /* Name of table or index */ path TEXT, /* Path to page from root */ pageno INTEGER, /* Page number */ pagetype TEXT, /* 'internal', 'leaf' or 'overflow' */ ncell INTEGER, /* Cells on page (0 for overflow) */ payload INTEGER, /* Bytes of payload on this page */ unused INTEGER, /* Bytes of unused space on this page */ mx_payload INTEGER, /* Largest payload size of all cells */ pgoffset INTEGER, /* Offset of page in file */ pgsize INTEGER, /* Size of the page */ schema TEXT HIDDEN /* Database schema being analyzed */); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger'); |
Source: softokn3.dll.1.dr | Binary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2); |
Source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr | Binary or memory string: CREATE TABLE xx( name TEXT, /* Name of table or index */ path TEXT, /* Path to page from root */ pageno INTEGER, /* Page number */ pagetype TEXT, /* 'internal', 'leaf' or 'overflow' */ ncell INTEGER, /* Cells on page (0 for overflow) */ payload INTEGER, /* Bytes of payload on this page */ unused INTEGER, /* Bytes of unused space on this page */ mx_payload INTEGER, /* Largest payload size of all cells */ pgoffset INTEGER, /* Offset of page in file */ pgsize INTEGER, /* Size of the page */ schema TEXT HIDDEN /* Database schema being analyzed */);/overflow%s%.3x+%.6x%s%.3x/internalleafcorruptedno such schema: %sSELECT 'sqlite_master' AS name, 1 AS rootpage, 'table' AS type UNION ALL SELECT name, rootpage, type FROM "%w".%s WHERE rootpage!=0 ORDER BY namedbstat2018-01-22 18:45:57 0c55d179733b46d8d0ba4d88e01a25e10677046ee3da1d5b1581e86726f2171d: |
Source: sqlite3.dll.1.dr | Binary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode); |
Source: unknown | Process created: C:\Users\user\Desktop\7SlKt2Puui.exe 'C:\Users\user\Desktop\7SlKt2Puui.exe' | |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q 'C:\Users\user\Desktop\7SlKt2Puui.exe' | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /T 10 /NOBREAK | |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q 'C:\Users\user\Desktop\7SlKt2Puui.exe' | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /T 10 /NOBREAK | Jump to behavior |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: freebl3.dll.1.dr |
Source: | Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: api-ms-win-crt-locale-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\gfx\angle\targets\libEGL\libEGL.pdb source: libEGL.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libprldap\prldap60.pdb source: prldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: api-ms-win-crt-runtime-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\ia2\IA2Marshal.pdb source: IA2Marshal.dll.1.dr |
Source: | Binary string: C:\coselu88\cez-yizuyine80_zesudu_peyihubitigufajuzad doseka.pdbpo.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss3.pdb source: 7SlKt2Puui.exe, 00000001.00000002.698512852.000000006D570000.00000002.00020000.sdmp, nss3.dll.1.dr |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: api-ms-win-core-file-l1-2-0.dll.1.dr |
Source: | Binary string: ucrtbase.pdb source: ucrtbase.dll.1.dr |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: api-ms-win-core-memory-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: api-ms-win-core-sysinfo-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldap\ldap60.pdb source: ldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: api-ms-win-crt-filesystem-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: api-ms-win-crt-stdio-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: api-ms-win-core-heap-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-util-l1-1-0.pdb source: api-ms-win-core-util-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-synch-l1-1-0.pdb source: api-ms-win-core-synch-l1-1-0.dll.1.dr |
Source: | Binary string: vcruntime140.i386.pdbGCTL source: vcruntime140.dll.1.dr |
Source: | Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: api-ms-win-crt-environment-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: softokn3.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\ckfw\builtins\builtins_nssckbi\nssckbi.pdb source: nssckbi.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\mozglue\build\mozglue.pdb22! source: 7SlKt2Puui.exe, 00000001.00000002.698110075.000000006D469000.00000002.00020000.sdmp, mozglue.dll.1.dr |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: api-ms-win-core-processthreads-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: freebl3.dll.1.dr |
Source: | Binary string: C:\coselu88\cez-yizuyine80_zesudu_peyihubitigufajuzad doseka.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: api-ms-win-crt-private-l1-1-0.pdb source: api-ms-win-crt-private-l1-1-0.dll.1.dr |
Source: | Binary string: po.pdb source: 7SlKt2Puui.exe |
Source: | Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: api-ms-win-crt-convert-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\ipc\win\handler\AccessibleHandler.pdb source: AccessibleHandler.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb-- source: nssdbm3.dll.1.dr |
Source: | Binary string: msvcp140.i386.pdb source: msvcp140.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\mailnews\mapi\mapihook\build\MapiProxy.pdb source: MapiProxy_InUse.dll.1.dr |
Source: | Binary string: ucrtbase.pdbUGP source: ucrtbase.dll.1.dr |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldap\ldap60.pdbUU source: ldap60.dll.1.dr |
Source: | Binary string: api-ms-win-crt-time-l1-1-0.pdb source: api-ms-win-crt-time-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\ckfw\builtins\builtins_nssckbi\nssckbi.pdb66 source: nssckbi.dll.1.dr |
Source: | Binary string: api-ms-win-core-handle-l1-1-0.pdb source: api-ms-win-core-handle-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-synch-l1-2-0.pdb source: api-ms-win-core-synch-l1-2-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: softokn3.dll.1.dr |
Source: | Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: api-ms-win-core-processenvironment-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\ia2\IA2Marshal.pdb<< source: IA2Marshal.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\mozglue\build\mozglue.pdb source: 7SlKt2Puui.exe, 00000001.00000002.698110075.000000006D469000.00000002.00020000.sdmp, mozglue.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\toolkit\library\dummydll\qipcap.pdb source: qipcap.dll.1.dr |
Source: | Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: api-ms-win-crt-conio-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-localization-l1-2-0.pdb source: api-ms-win-core-localization-l1-2-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-math-l1-1-0.pdb source: api-ms-win-crt-math-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: api-ms-win-core-processthreads-l1-1-1.dll.1.dr |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: api-ms-win-core-namedpipe-l1-1-0.dll.1.dr |
Source: | Binary string: vcruntime140.i386.pdb source: vcruntime140.dll.1.dr |
Source: | Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: api-ms-win-crt-multibyte-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: api-ms-win-crt-utility-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\mailnews\mapi\mapiDLL\mozMapi32.pdb source: mozMapi32.dll.1.dr |
Source: | Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: api-ms-win-core-rtlsupport-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: api-ms-win-core-timezone-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-string-l1-1-0.pdb source: api-ms-win-core-string-l1-1-0.dll.1.dr |
Source: | Binary string: msvcp140.i386.pdbGCTL source: msvcp140.dll.1.dr |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: api-ms-win-core-file-l2-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-process-l1-1-0.pdb source: api-ms-win-crt-process-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: api-ms-win-core-libraryloader-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\comm\ldap\c-sdk\libraries\libldif\ldif60.pdb source: ldif60.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\config\external\lgpllibs\lgpllibs.pdb source: lgpllibs.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\accessible\interfaces\msaa\AccessibleMarshal.pdb source: AccessibleMarshal.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb source: nssdbm3.dll.1.dr |
Source: | Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: api-ms-win-core-interlocked-l1-1-0.dll.1.dr |
Source: | Binary string: z:\task_1552562425\build\src\obj-thunderbird\toolkit\crashreporter\injector\breakpadinjector.pdb source: breakpadinjector.dll.1.dr |
Source: | Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: api-ms-win-crt-heap-l1-1-0.dll.1.dr |
Source: | Binary string: api-ms-win-crt-string-l1-1-0.pdb source: api-ms-win-crt-string-l1-1-0.dll.1.dr |
Source: 7SlKt2Puui.exe | Static PE information: section name: .xozoxew |
Source: sqlite3.dll.1.dr | Static PE information: section name: /4 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /19 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /31 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /45 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /57 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /70 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /81 |
Source: sqlite3.dll.1.dr | Static PE information: section name: /92 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\nssdbm3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\MapiProxy_InUse.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\freebl3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\sqlite3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\softokn3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\AccessibleMarshal.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\ldap60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\vcruntime140.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\ucrtbase.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\qipcap.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\lgpllibs.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\mozMapi32_InUse.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\ldif60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\prldap60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\mozMapi32.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\mozglue.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\nss3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\breakpadinjector.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\MapiProxy.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\nssckbi.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\AccessibleHandler.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\msvcp140.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\IA2Marshal.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | File created: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\libEGL.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Code function: 1_2_0041DD64 __EH_prolog,SetCurrentDirectoryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, | 1_2_0041DD64 |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\nssdbm3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\MapiProxy_InUse.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\freebl3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\softokn3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\AccessibleMarshal.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\ldap60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\qipcap.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\lgpllibs.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\mozMapi32_InUse.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\ldif60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\prldap60.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui.exe | Dropped PE file which has not been started: C:\Users\user\AppData\LocalLow\gC9tT2iQ3s\mozMapi32.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\7SlKt2Puui |