Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,GetMenuState,LocalFree, |
2_2_0040C4B7 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040E511 CryptUnprotectData,LocalFree, |
2_2_0040E511 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
2_2_0040EDD6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
2_2_0040D290 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,GetMenuState,LocalFree, |
2_1_0040C4B7 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040E511 CryptUnprotectData,LocalFree, |
2_1_0040E511 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
2_1_0040EDD6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
2_1_0040D290 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
6_2_0040C4B7 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040E511 CryptUnprotectData,LocalFree, |
6_2_0040E511 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
6_2_0040EDD6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
6_2_0040D290 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
6_1_0040C4B7 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040E511 CryptUnprotectData,LocalFree, |
6_1_0040E511 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
6_1_0040EDD6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
6_1_0040D290 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
9_2_0040C4B7 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040E511 CryptUnprotectData,LocalFree, |
9_2_0040E511 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
9_2_0040EDD6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
9_2_0040D290 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
1_2_00405302 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_00405CD8 FindFirstFileA,FindClose, |
1_2_00405CD8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_0040263E FindFirstFileA, |
1_2_0040263E |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_2_00406453 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
2_2_0040680D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
2_2_0040753D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_2_00413A85 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
2_2_0040DB1C |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
2_2_00406F83 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
2_2_00406390 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_1_00406453 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
2_1_0040680D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
2_1_0040753D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_1_00413A85 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
2_1_0040DB1C |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
2_1_00406F83 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
2_1_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_2_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
6_2_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
6_2_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_2_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
6_2_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
6_2_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
6_2_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_1_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
6_1_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
6_1_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_1_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
6_1_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
6_1_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
6_1_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
7_2_00405302 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_00405CD8 FindFirstFileA,FindClose, |
7_2_00405CD8 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_0040263E FindFirstFileA, |
7_2_0040263E |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
9_2_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
9_2_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
9_2_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
9_2_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
9_2_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
9_2_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
9_2_00406390 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
2_2_00409953 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
2_1_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
6_2_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
6_1_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
9_2_00409953 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
2_2_00409953 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
2_1_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
6_2_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
6_1_00409953 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
9_2_00409953 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_004046CA |
1_2_004046CA |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_00405FA8 |
1_2_00405FA8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_73861A98 |
1_2_73861A98 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00403047 |
2_2_00403047 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0041D049 |
2_2_0041D049 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00419463 |
2_2_00419463 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00415079 |
2_2_00415079 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00420420 |
2_2_00420420 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_004208C0 |
2_2_004208C0 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_004034D3 |
2_2_004034D3 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00414976 |
2_2_00414976 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00402E68 |
2_2_00402E68 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00416619 |
2_2_00416619 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040AEC6 |
2_2_0040AEC6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00402AFC |
2_2_00402AFC |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00415ABF |
2_2_00415ABF |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00420F40 |
2_2_00420F40 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0041FF50 |
2_2_0041FF50 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040A728 |
2_2_0040A728 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00403047 |
2_1_00403047 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0041D049 |
2_1_0041D049 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00419463 |
2_1_00419463 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00415079 |
2_1_00415079 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00420420 |
2_1_00420420 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_004208C0 |
2_1_004208C0 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_004034D3 |
2_1_004034D3 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00414976 |
2_1_00414976 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00402E68 |
2_1_00402E68 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00416619 |
2_1_00416619 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040AEC6 |
2_1_0040AEC6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00402AFC |
2_1_00402AFC |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00415ABF |
2_1_00415ABF |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00420F40 |
2_1_00420F40 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0041FF50 |
2_1_0041FF50 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040A728 |
2_1_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00403047 |
6_2_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0041D049 |
6_2_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00419463 |
6_2_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00415079 |
6_2_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00420420 |
6_2_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_004208C0 |
6_2_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_004034D3 |
6_2_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00414976 |
6_2_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00402E68 |
6_2_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00416619 |
6_2_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040AEC6 |
6_2_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00402AFC |
6_2_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00415ABF |
6_2_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00420F40 |
6_2_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0041FF50 |
6_2_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040A728 |
6_2_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00403047 |
6_1_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0041D049 |
6_1_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00419463 |
6_1_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00415079 |
6_1_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00420420 |
6_1_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_004208C0 |
6_1_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_004034D3 |
6_1_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00414976 |
6_1_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00402E68 |
6_1_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00416619 |
6_1_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040AEC6 |
6_1_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00402AFC |
6_1_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00415ABF |
6_1_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00420F40 |
6_1_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0041FF50 |
6_1_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040A728 |
6_1_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_004046CA |
7_2_004046CA |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_00405FA8 |
7_2_00405FA8 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00403047 |
9_2_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0041D049 |
9_2_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00419463 |
9_2_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00415079 |
9_2_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00420420 |
9_2_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_004208C0 |
9_2_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_004034D3 |
9_2_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00414976 |
9_2_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00402E68 |
9_2_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00416619 |
9_2_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040AEC6 |
9_2_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00402AFC |
9_2_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00415ABF |
9_2_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00420F40 |
9_2_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0041FF50 |
9_2_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040A728 |
9_2_0040A728 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_73862F60 push eax; ret |
1_2_73862F8E |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00409E61 push eax; mov dword ptr [esp], ebx |
2_2_00409FDE |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DCE9 push ecx; mov dword ptr [esp], 00423976h |
2_2_0040DD9F |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DCE9 push ebp; mov dword ptr [esp], 0042398Ah |
2_2_0040DDD9 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DCE9 push edx; mov dword ptr [esp], 00423997h |
2_2_0040DDF7 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DCE9 push edx; mov dword ptr [esp], esi |
2_2_0040E394 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040A4BC push esi; mov dword ptr [esp], 00423347h |
2_2_0040A543 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00409953 push edi; mov dword ptr [esp], 00000091h |
2_2_00409980 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00409953 push ebp; mov dword ptr [esp], 00000090h |
2_2_0040998D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00411D8C push edx; mov dword ptr [esp], edi |
2_2_00412058 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406E04 push ecx; mov dword ptr [esp], ebx |
2_2_00406E69 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
2_2_004027C8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
2_2_00402815 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
2_2_004029B2 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_004146E1 push eax; mov dword ptr [esp], ebx |
2_2_0041470B |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040970C push eax; mov dword ptr [esp], 0042B4A0h |
2_2_004097B9 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00409E61 push eax; mov dword ptr [esp], ebx |
2_1_00409FDE |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DCE9 push ecx; mov dword ptr [esp], 00423976h |
2_1_0040DD9F |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DCE9 push ebp; mov dword ptr [esp], 0042398Ah |
2_1_0040DDD9 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DCE9 push edx; mov dword ptr [esp], 00423997h |
2_1_0040DDF7 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DCE9 push edx; mov dword ptr [esp], esi |
2_1_0040E394 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040A4BC push esi; mov dword ptr [esp], 00423347h |
2_1_0040A543 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00409953 push edi; mov dword ptr [esp], 00000091h |
2_1_00409980 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00409953 push ebp; mov dword ptr [esp], 00000090h |
2_1_0040998D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00411D8C push edx; mov dword ptr [esp], edi |
2_1_00412058 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406E04 push ecx; mov dword ptr [esp], ebx |
2_1_00406E69 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
2_1_004027C8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
2_1_00402815 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
2_1_004029B2 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_004146E1 push eax; mov dword ptr [esp], ebx |
2_1_0041470B |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040970C push eax; mov dword ptr [esp], 0042B4A0h |
2_1_004097B9 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
1_2_00405302 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_00405CD8 FindFirstFileA,FindClose, |
1_2_00405CD8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 1_2_0040263E FindFirstFileA, |
1_2_0040263E |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_2_00406453 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
2_2_0040680D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
2_2_0040753D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_2_00413A85 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
2_2_0040DB1C |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
2_2_00406F83 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
2_2_00406390 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_1_00406453 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
2_1_0040680D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
2_1_0040753D |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
2_1_00413A85 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
2_1_0040DB1C |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
2_1_00406F83 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe |
Code function: 2_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
2_1_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_2_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
6_2_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
6_2_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_2_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
6_2_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
6_2_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
6_2_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_1_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
6_1_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
6_1_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
6_1_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
6_1_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
6_1_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 6_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
6_1_00406390 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
7_2_00405302 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_00405CD8 FindFirstFileA,FindClose, |
7_2_00405CD8 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 7_2_0040263E FindFirstFileA, |
7_2_0040263E |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
9_2_00406453 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
9_2_0040680D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
9_2_0040753D |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
9_2_00413A85 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
9_2_0040DB1C |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
9_2_00406F83 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe |
Code function: 9_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
9_2_00406390 |
Source: Yara match |
File source: 00000002.00000001.363673900.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000002.406739098.00000000023A0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000006.00000002.394088134.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000006.00000001.393727825.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.395120542.00000000024E0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000009.00000001.405669006.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.367065114.00000000024C0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.621612280.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000009.00000002.406157548.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: US1pwXib6h.exe PID: 6476, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ioldfli.exe PID: 6768, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ioldfli.exe PID: 7088, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: US1pwXib6h.exe PID: 6548, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ioldfli.exe PID: 7012, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ioldfli.exe PID: 6824, type: MEMORY |
Source: Yara match |
File source: 1.2.US1pwXib6h.exe.24c0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.1.US1pwXib6h.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.ioldfli.exe.24e0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.1.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.US1pwXib6h.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.US1pwXib6h.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.1.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.1.US1pwXib6h.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 9.1.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 9.2.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.2.ioldfli.exe.23a0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.2.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 9.2.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 9.1.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.2.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |