Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.178.120.24 |
Source: CasPol.exe, 00000009.00000002.5806993924.000000001D5E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: ftp://ftp.gettoner.com.mx/droid |
Source: CasPol.exe, 00000009.00000002.5806993924.000000001D5E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: CasPol.exe, 00000009.00000002.5786454694.0000000001396000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://195.178.120.24/mhpgXW188.chm |
Source: CasPol.exe, 00000009.00000002.5806993924.000000001D5E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: CasPol.exe, 00000009.00000002.5806993924.000000001D5E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://NwSpLV.com |
Source: 6culQoI97a.exe | String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: 6culQoI97a.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: CasPol.exe, 00000009.00000002.5806993924.000000001D5E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_00405339 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_00403325 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_73DD1A98 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EDEC82 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE02EE |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC76FF |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB2CF |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC72DB |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC76BA |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBE84 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6E7B |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC824F |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6E46 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EDEE46 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6E47 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBA0D |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB3F8 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB7CA |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC73A9 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6FA3 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC73BD |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE3FBA |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE137C |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE0B71 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC8B4B |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE433C |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB4E3 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC70C8 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC88D9 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC8841 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ED2824 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC7801 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC35EB |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC71EB |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC89FD |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC85F3 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECA9A0 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB1B5 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC359E |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE0997 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB17E |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE1D76 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBD71 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBD09 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011DDD83 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011DE1D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011DB025 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011D83E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011D4928 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011DA0D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_011D1BD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_0124C510 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_01244168 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_012455E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_0124D8F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_01246790 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_012496F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_01243179 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_012425E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_012437B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D445D08 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D444EF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D4469D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D444374 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D445C41 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D4469F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F88BE70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F884320 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F88B110 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F881130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F883708 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1F883A50 |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_00403325 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_73DD2F60 push eax; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC514F push edi; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC9AEB pushad ; retf |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC56C8 push ds; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC3ACA push esp; iretd |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECC658 push cs; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC4BE4 push 6B8BC5CBh; retf |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC3FB0 push ss; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC537B push edi; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC24CD push esp; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC145C pushad ; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC517A push edi; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC4D44 push ebx; retf |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECC13C pushfd ; retn BE8Dh |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_0124142F push edi; retn 0000h |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Code function: 9_2_1D444C51 push ds; ret |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Guest Shutdown Service |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Remote Desktop Virtualization Service |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmicshutdown |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Volume Shadow Copy Requestor |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V PowerShell Direct Service |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Time Synchronization Service |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmicvss |
Source: CasPol.exe, 00000009.00000002.5787444252.00000000013C5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: CasPol.exe, 00000009.00000002.5785252784.000000000135B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWH |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Data Exchange Service |
Source: 6culQoI97a.exe, 00000002.00000002.1203249010.0000000000A28000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exepGz |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Heartbeat Service |
Source: 6culQoI97a.exe, 00000002.00000002.1203507076.0000000000A5B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Program Files\Qemu-ga\qemu-ga.exe |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V Guest Service Interface |
Source: 6culQoI97a.exe, 00000002.00000002.1204307572.0000000003049000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmicheartbeat |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6E46 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EC6E47 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBA0D mov ebx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBA0D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECBBF7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB7CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECA44C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB84D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB80E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EDFDE9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB960 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECB17E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02EE1D76 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_02ECC936 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Source: C:\Users\user\Desktop\6culQoI97a.exe | Code function: 2_2_00403325 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |