Source: Yara match | File source: jrC504LJVe.dll, type: SAMPLE |
Source: Yara match | File source: 00000002.00000002.507194877.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.529754214.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.501190054.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.513290873.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.507194291.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.537272561.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.525353874.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 2.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 14.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll32.exe.6e1e0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: jrC504LJVe.dll, type: SAMPLE |
Source: Yara match | File source: 00000002.00000002.507194877.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.529754214.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.501190054.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.513290873.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.507194291.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.537272561.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.525353874.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 2.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 14.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll32.exe.6e1e0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E223E00 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E221C3C |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E2567D9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E2484BB |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E2602BC |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E250396 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E23E079 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E235150 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E223E00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E2567D9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E221C3C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E2484BB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E2602BC |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E250396 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E23E079 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E235150 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4808:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6944:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5668:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6724:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6388:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6504:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6236:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3412:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1304:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5808:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6440:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5516:120:WilError_01 |
Source: unknown | Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll' |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll',#1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Connectdark |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll',#1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Mindlake |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Porthigh |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Problemscale |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,WingGrass |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll',#1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Connectdark |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Mindlake |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,Problemscale |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\jrC504LJVe.dll,WingGrass |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll',#1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: Yara match | File source: jrC504LJVe.dll, type: SAMPLE |
Source: Yara match | File source: 00000002.00000002.507194877.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.529754214.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.501190054.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.513290873.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.507194291.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.537272561.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.525353874.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 2.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 14.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll32.exe.6e1e0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\rundll32.exe | Last function: Thread delayed |
Source: C:\Windows\SysWOW64\rundll32.exe | Last function: Thread delayed |
Source: C:\Windows\SysWOW64\rundll32.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E241F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E2207A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E220288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E241F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E2207A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E220288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\jrC504LJVe.dll',#1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Source: loaddll32.exe, 00000000.00000002.501134012.00000000013C0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.483282253.00000000033D0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.481774524.0000000003530000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.537147837.0000000003820000.00000002.00000001.sdmp, rundll32.exe, 00000011.00000002.514327725.0000000003870000.00000002.00000001.sdmp, rundll32.exe, 00000016.00000002.520658542.0000000002CE0000.00000002.00000001.sdmp, rundll32.exe, 0000001B.00000002.513252331.0000000002D40000.00000002.00000001.sdmp | Binary or memory string: Program Manager |
Source: loaddll32.exe, 00000000.00000002.501134012.00000000013C0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.483282253.00000000033D0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.481774524.0000000003530000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.537147837.0000000003820000.00000002.00000001.sdmp, rundll32.exe, 00000011.00000002.514327725.0000000003870000.00000002.00000001.sdmp, rundll32.exe, 00000016.00000002.520658542.0000000002CE0000.00000002.00000001.sdmp, rundll32.exe, 0000001B.00000002.513252331.0000000002D40000.00000002.00000001.sdmp | Binary or memory string: Shell_TrayWnd |
Source: loaddll32.exe, 00000000.00000002.501134012.00000000013C0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.483282253.00000000033D0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.481774524.0000000003530000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.537147837.0000000003820000.00000002.00000001.sdmp, rundll32.exe, 00000011.00000002.514327725.0000000003870000.00000002.00000001.sdmp, rundll32.exe, 00000016.00000002.520658542.0000000002CE0000.00000002.00000001.sdmp, rundll32.exe, 0000001B.00000002.513252331.0000000002D40000.00000002.00000001.sdmp | Binary or memory string: Progman |
Source: loaddll32.exe, 00000000.00000002.501134012.00000000013C0000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.483282253.00000000033D0000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.481774524.0000000003530000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.537147837.0000000003820000.00000002.00000001.sdmp, rundll32.exe, 00000011.00000002.514327725.0000000003870000.00000002.00000001.sdmp, rundll32.exe, 00000016.00000002.520658542.0000000002CE0000.00000002.00000001.sdmp, rundll32.exe, 0000001B.00000002.513252331.0000000002D40000.00000002.00000001.sdmp | Binary or memory string: Progmanlock |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: ___crtGetLocaleInfoEx, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: ___crtGetLocaleInfoEx, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: Yara match | File source: jrC504LJVe.dll, type: SAMPLE |
Source: Yara match | File source: 00000002.00000002.507194877.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.529754214.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.501190054.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.513290873.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.507194291.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.537272561.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.525353874.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 2.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 14.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll32.exe.6e1e0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: jrC504LJVe.dll, type: SAMPLE |
Source: Yara match | File source: 00000002.00000002.507194877.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.529754214.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.501190054.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.513290873.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.507194291.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.537272561.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.525353874.000000006E1E1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 2.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 14.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 27.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll32.exe.6e1e0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.rundll32.exe.6e1e0000.1.unpack, type: UNPACKEDPE |