Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000000.00000002.917348475.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000002.00000002.962266346.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000003.00000002.966549203.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.966145648.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000010.00000002.964938469.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000015.00000002.921321344.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000018.00000002.959988796.000000006D4EA000.00000002.00020000.sdmp, n8x3d68Gnd.dll |
Source: Yara match |
File source: n8x3d68Gnd.dll, type: SAMPLE |
Source: Yara match |
File source: 00000018.00000002.945736297.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000003.00000002.949353578.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000D.00000002.945539240.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.962212872.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.944163100.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.917299629.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.921268168.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.loaddll32.exe.6d460000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 3.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 13.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: n8x3d68Gnd.dll, type: SAMPLE |
Source: Yara match |
File source: 00000018.00000002.945736297.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000003.00000002.949353578.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000D.00000002.945539240.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.962212872.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.944163100.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.917299629.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.921268168.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.loaddll32.exe.6d460000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 3.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 13.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4A1C3C |
0_2_6D4A1C3C |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4A3E00 |
0_2_6D4A3E00 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4C84BB |
0_2_6D4C84BB |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4D67D9 |
0_2_6D4D67D9 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4B5150 |
0_2_6D4B5150 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4BE079 |
0_2_6D4BE079 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4D0396 |
0_2_6D4D0396 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4E02BC |
0_2_6D4E02BC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4A1C3C |
2_2_6D4A1C3C |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4A3E00 |
2_2_6D4A3E00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4C84BB |
2_2_6D4C84BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4D67D9 |
2_2_6D4D67D9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4B5150 |
2_2_6D4B5150 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4BE079 |
2_2_6D4BE079 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4D0396 |
2_2_6D4D0396 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4E02BC |
2_2_6D4E02BC |
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6D4A0990 appears 34 times |
|
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6D4A00AC appears 100 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6D4A0990 appears 34 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6D4A00AC appears 100 times |
|
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4112:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6344:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6596:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6560:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6820:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4800:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2212:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4820:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4164:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7120:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6728:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6768:120:WilError_01 |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll' |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll',#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Connectdark |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll',#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Mindlake |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Porthigh |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Problemscale |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,WingGrass |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Connectdark |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Mindlake |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Porthigh |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,Problemscale |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\n8x3d68Gnd.dll,WingGrass |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000000.00000002.917348475.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000002.00000002.962266346.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000003.00000002.966549203.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.966145648.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000010.00000002.964938469.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000015.00000002.921321344.000000006D4EA000.00000002.00020000.sdmp, rundll32.exe, 00000018.00000002.959988796.000000006D4EA000.00000002.00020000.sdmp, n8x3d68Gnd.dll |
Source: Yara match |
File source: n8x3d68Gnd.dll, type: SAMPLE |
Source: Yara match |
File source: 00000018.00000002.945736297.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000003.00000002.949353578.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000D.00000002.945539240.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.962212872.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.944163100.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.917299629.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.921268168.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.loaddll32.exe.6d460000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 3.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 13.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4C1F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_6D4C1F6D |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4A07A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_6D4A07A7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_6D4A0288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_6D4A0288 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4C1F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6D4C1F6D |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4A07A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6D4A07A7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 2_2_6D4A0288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
2_2_6D4A0288 |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\n8x3d68Gnd.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: loaddll32.exe, 00000000.00000002.917246686.0000000001A20000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.957190907.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.932674972.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 0000000D.00000002.928824378.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000010.00000002.927424186.0000000003780000.00000002.00000001.sdmp, rundll32.exe, 00000015.00000002.921221388.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.929091942.00000000030B0000.00000002.00000001.sdmp |
Binary or memory string: Program Manager |
Source: loaddll32.exe, 00000000.00000002.917246686.0000000001A20000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.957190907.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.932674972.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 0000000D.00000002.928824378.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000010.00000002.927424186.0000000003780000.00000002.00000001.sdmp, rundll32.exe, 00000015.00000002.921221388.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.929091942.00000000030B0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: loaddll32.exe, 00000000.00000002.917246686.0000000001A20000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.957190907.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.932674972.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 0000000D.00000002.928824378.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000010.00000002.927424186.0000000003780000.00000002.00000001.sdmp, rundll32.exe, 00000015.00000002.921221388.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.929091942.00000000030B0000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: loaddll32.exe, 00000000.00000002.917246686.0000000001A20000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.957190907.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.932674972.00000000030B0000.00000002.00000001.sdmp, rundll32.exe, 0000000D.00000002.928824378.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000010.00000002.927424186.0000000003780000.00000002.00000001.sdmp, rundll32.exe, 00000015.00000002.921221388.0000000003440000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.929091942.00000000030B0000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\System32\loaddll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
0_2_6D4DDD96 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6D4DDF65 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6D4D3952 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_6D4DE518 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6D4DE61F |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
0_2_6D4DE6EC |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6D4DE112 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
0_2_6D4DE19F |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6D49F1B7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6D4DE077 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
0_2_6D4DE00E |
Source: C:\Windows\System32\loaddll32.exe |
Code function: ___crtGetLocaleInfoEx, |
0_2_6D49F364 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6D4D4323 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
0_2_6D4DE3EF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
2_2_6D4DDD96 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6D4DDF65 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6D4D3952 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
2_2_6D4DE518 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6D4DE61F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6D4DE6EC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6D4DE112 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6D4DE19F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6D49F1B7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6D4DE077 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6D4DE00E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: ___crtGetLocaleInfoEx, |
2_2_6D49F364 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6D4D4323 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
2_2_6D4DE3EF |
Source: Yara match |
File source: n8x3d68Gnd.dll, type: SAMPLE |
Source: Yara match |
File source: 00000018.00000002.945736297.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000003.00000002.949353578.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000D.00000002.945539240.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.962212872.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.944163100.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.917299629.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.921268168.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.loaddll32.exe.6d460000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 3.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 13.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: n8x3d68Gnd.dll, type: SAMPLE |
Source: Yara match |
File source: 00000018.00000002.945736297.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000003.00000002.949353578.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000D.00000002.945539240.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.962212872.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.944163100.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.917299629.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.921268168.000000006D461000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.loaddll32.exe.6d460000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 3.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 13.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.rundll32.exe.6d460000.1.unpack, type: UNPACKEDPE |