Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000000.00000002.608295285.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000002.00000002.534934724.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000003.00000002.619699878.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 0000000C.00000002.537317652.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 0000000F.00000002.575775840.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000014.00000002.619037007.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000019.00000002.574975507.000000006DD7A000.00000002.00020000.sdmp, kS5hYPcgm8.dll |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD31C3C |
0_2_6DD31C3C |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD33E00 |
0_2_6DD33E00 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD584BB |
0_2_6DD584BB |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD667D9 |
0_2_6DD667D9 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD45150 |
0_2_6DD45150 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD4E079 |
0_2_6DD4E079 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD60396 |
0_2_6DD60396 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD702BC |
0_2_6DD702BC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD584BB |
2_2_6DD584BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD31C3C |
2_2_6DD31C3C |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD667D9 |
2_2_6DD667D9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD33E00 |
2_2_6DD33E00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD45150 |
2_2_6DD45150 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD4E079 |
2_2_6DD4E079 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD60396 |
2_2_6DD60396 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD702BC |
2_2_6DD702BC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DCF2264 |
3_2_6DCF2264 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD584BB |
3_2_6DD584BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD31C3C |
3_2_6DD31C3C |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD33E00 |
3_2_6DD33E00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD45150 |
3_2_6DD45150 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD60396 |
3_2_6DD60396 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6DD30990 appears 34 times |
|
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6DD300AC appears 100 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6DD30990 appears 56 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6DD300AC appears 193 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6DD300E0 appears 47 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6DD523A9 appears 33 times |
|
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6404:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6248:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7036:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6512:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7104:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6260:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6348:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4228:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6148:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6924:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6428:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6728:120:WilError_01 |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll' |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll',#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Connectdark |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll',#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Mindlake |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Porthigh |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Problemscale |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,WingGrass |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Connectdark |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Mindlake |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Porthigh |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,Problemscale |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\kS5hYPcgm8.dll,WingGrass |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000000.00000002.608295285.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000002.00000002.534934724.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000003.00000002.619699878.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 0000000C.00000002.537317652.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 0000000F.00000002.575775840.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000014.00000002.619037007.000000006DD7A000.00000002.00020000.sdmp, rundll32.exe, 00000019.00000002.574975507.000000006DD7A000.00000002.00020000.sdmp, kS5hYPcgm8.dll |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD309D6 push ecx; ret |
0_2_6DD309E9 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD30075 push ecx; ret |
0_2_6DD30088 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD309D6 push ecx; ret |
2_2_6DD309E9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD30075 push ecx; ret |
2_2_6DD30088 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DCF2253 push ecx; ret |
3_2_6DCF2263 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DCF2200 push ecx; ret |
3_2_6DCF2209 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD309D6 push ecx; ret |
3_2_6DD309E9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD30075 push ecx; ret |
3_2_6DD30088 |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD51F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_6DD51F6D |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD307A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_6DD307A7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6DD30288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_6DD30288 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD307A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6DD307A7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD51F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6DD51F6D |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6DD30288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
2_2_6DD30288 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD51F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
3_2_6DD51F6D |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6DD30288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
3_2_6DD30288 |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\kS5hYPcgm8.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: loaddll32.exe, 00000000.00000002.576781232.0000000000EE0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.534853952.00000000034B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.610554445.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 0000000C.00000002.534015445.00000000030F0000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.526747254.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 00000014.00000002.610139527.00000000038A0000.00000002.00000001.sdmp, rundll32.exe, 00000019.00000002.525740389.0000000002D90000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: loaddll32.exe, 00000000.00000002.576781232.0000000000EE0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.534853952.00000000034B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.610554445.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 0000000C.00000002.534015445.00000000030F0000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.526747254.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 00000014.00000002.610139527.00000000038A0000.00000002.00000001.sdmp, rundll32.exe, 00000019.00000002.525740389.0000000002D90000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: loaddll32.exe, 00000000.00000002.576781232.0000000000EE0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.534853952.00000000034B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.610554445.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 0000000C.00000002.534015445.00000000030F0000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.526747254.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 00000014.00000002.610139527.00000000038A0000.00000002.00000001.sdmp, rundll32.exe, 00000019.00000002.525740389.0000000002D90000.00000002.00000001.sdmp |
Binary or memory string: SProgram Managerl |
Source: loaddll32.exe, 00000000.00000002.576781232.0000000000EE0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.534853952.00000000034B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.610554445.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 0000000C.00000002.534015445.00000000030F0000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.526747254.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 00000014.00000002.610139527.00000000038A0000.00000002.00000001.sdmp, rundll32.exe, 00000019.00000002.525740389.0000000002D90000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: loaddll32.exe, 00000000.00000002.576781232.0000000000EE0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.534853952.00000000034B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.610554445.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 0000000C.00000002.534015445.00000000030F0000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.526747254.0000000002D90000.00000002.00000001.sdmp, rundll32.exe, 00000014.00000002.610139527.00000000038A0000.00000002.00000001.sdmp, rundll32.exe, 00000019.00000002.525740389.0000000002D90000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\System32\loaddll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
0_2_6DD6DD96 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6DD6DF65 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6DD63952 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_6DD6E518 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
0_2_6DD6E6EC |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6DD6E61F |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
0_2_6DD6E19F |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6DD2F1B7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6DD6E112 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6DD6E077 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6DD6E00E |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6DD6E3EF |
Source: C:\Windows\System32\loaddll32.exe |
Code function: ___crtGetLocaleInfoEx, |
0_2_6DD2F364 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6DD64323 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
2_2_6DD6DD96 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
2_2_6DD6E518 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6DD6DF65 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6DD6E6EC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6DD6E61F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6DD6E19F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6DD2F1B7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6DD63952 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6DD6E112 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6DD6E077 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6DD6E00E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6DD6E3EF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: ___crtGetLocaleInfoEx, |
2_2_6DD2F364 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6DD64323 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoA,GetSystemDefaultUILanguage,VerLanguageNameA, |
3_2_6DCF1566 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
3_2_6DD6DD96 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
3_2_6DD6E518 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
3_2_6DD6E6EC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
3_2_6DD2F1B7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
3_2_6DD63952 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
3_2_6DD6E112 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
3_2_6DD6E077 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
3_2_6DD6E00E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: ___crtGetLocaleInfoEx, |
3_2_6DD2F364 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
3_2_6DD64323 |