Windows Analysis Report
SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe

Overview

General Information

Sample Name: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Analysis ID: 755940
MD5: 55d6460392408d1325c18b69a91c28e3
SHA1: 405847d03be406a0025eda76852dfd46420a8d7a
SHA256: d1e9780a620ddf149c2aed319388bca7ed690c2a58c9ffc8f60b1c4515115dc9
Tags: exe
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Yara detected AntiVM3
System process connects to network (likely due to code injection or exploit)
Sigma detected: Scheduled temp file as task from temp location
Antivirus detection for URL or domain
Multi AV Scanner detection for dropped file
Sample uses process hollowing technique
Tries to steal Mail credentials (via file / registry access)
Maps a DLL or memory area into another process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Injects a PE file into a foreign processes
Queues an APC in another process (thread injection)
Machine Learning detection for dropped file
Modifies the context of a thread in another process (thread injection)
C2 URLs / IPs found in malware configuration
Adds a directory exclusion to Windows Defender
Uses schtasks.exe or at.exe to add and modify task schedules
Tries to harvest and steal browser information (history, passwords, etc)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to call native functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Drops PE files
Contains functionality to read the PEB
Checks if the current process is being debugged
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

AV Detection

barindex
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe ReversingLabs: Detection: 29%
Source: Yara match File source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: http://www.somethingyourselves.com/n2hm/?bN=9gwJr9Ib0rEc+KDTQOrHkeZIL+750DWB0cIboGlmlHlNjyJ/Euut2Sz1G3s+yPgqLfhiB/VwLZOXrNsbN5gXgWVJl9cnSs3fxA==&TpfpO=3fCD1To0u Avira URL Cloud: Label: malware
Source: www.madamkikkiey.net/n2hm/ Avira URL Cloud: Label: malware
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe ReversingLabs: Detection: 29%
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Joe Sandbox ML: detected
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp Malware Configuration Extractor: FormBook {"C2 list": ["www.madamkikkiey.net/n2hm/"]}
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.359410400.000000000194A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000002.361323624.0000000001AE0000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.355211610.00000000017A7000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 0000000D.00000002.501948554.0000000001950000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.504620671.0000000003588000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.578060777.0000000003720000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.501310955.00000000033F0000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.581625002.000000000383F000.00000040.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.359410400.000000000194A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000002.361323624.0000000001AE0000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.355211610.00000000017A7000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 0000000D.00000002.501948554.0000000001950000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.504620671.0000000003588000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.578060777.0000000003720000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.501310955.00000000033F0000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.581625002.000000000383F000.00000040.00000800.00020000.00000000.sdmp

Networking

barindex
Source: C:\Windows\explorer.exe Domain query: www.somethingyourselves.com
Source: C:\Windows\explorer.exe Network Connect: 103.193.185.8 80
Source: Malware configuration extractor URLs: www.madamkikkiey.net/n2hm/
Source: Joe Sandbox View ASN Name: EHOSTIDC-AS-KREHOSTICTKR EHOSTIDC-AS-KREHOSTICTKR
Source: global traffic HTTP traffic detected: GET /n2hm/?bN=9gwJr9Ib0rEc+KDTQOrHkeZIL+750DWB0cIboGlmlHlNjyJ/Euut2Sz1G3s+yPgqLfhiB/VwLZOXrNsbN5gXgWVJl9cnSs3fxA==&TpfpO=3fCD1To0u HTTP/1.1Host: www.somethingyourselves.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii:
Source: Joe Sandbox View IP Address: 103.193.185.8 103.193.185.8
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 29 Nov 2022 09:43:45 GMTServer: ApacheContent-Type: text/htmlContent-Length: 1Vary: Accept-EncodingConnection: closeData Raw: 20 Data Ascii:
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://fontfabrik.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.361866159.0000000003151000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.390890604.00000000030C0000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359450288.00000000014C7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359450288.00000000014C7000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.como
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fonts.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000003.313238837.0000000005D88000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.c
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000003.313238837.0000000005D88000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000003.311383849.0000000005D9B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000003.311383849.0000000005D9B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.come
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000003.311383849.0000000005D9B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.comiv
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sakkal.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.tiro.com
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.typography.netD
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.365696843.0000000006F92000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: 17089-7.17.dr String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: 17089-7.17.dr String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
Source: 17089-7.17.dr String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: 17089-7.17.dr String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://search.yahoo.com?fr=crmas_sfp
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://search.yahoo.com?fr=crmas_sfpf
Source: cmd.exe, 00000011.00000003.571177133.00000000033B5000.00000004.00000020.00020000.00000000.sdmp, 17089-7.17.dr String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: unknown DNS traffic detected: queries for: www.somethingyourselves.com
Source: global traffic HTTP traffic detected: GET /n2hm/?bN=9gwJr9Ib0rEc+KDTQOrHkeZIL+750DWB0cIboGlmlHlNjyJ/Euut2Sz1G3s+yPgqLfhiB/VwLZOXrNsbN5gXgWVJl9cnSs3fxA==&TpfpO=3fCD1To0u HTTP/1.1Host: www.somethingyourselves.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii:

E-Banking Fraud

barindex
Source: Yara match File source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 7.2.FqJXaFxwEj.exe.2e02e38.0.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
Source: 7.2.FqJXaFxwEj.exe.2e20608.1.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2eb0724.1.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2e92f54.0.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0000000D.00000002.501723041.0000000001870000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe PID: 5616, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: Process Memory Space: FqJXaFxwEj.exe PID: 4460, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: Process Memory Space: cmd.exe PID: 3628, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 7.2.FqJXaFxwEj.exe.2e02e38.0.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
Source: 7.2.FqJXaFxwEj.exe.2e20608.1.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2eb0724.1.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2e92f54.0.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0000000D.00000002.501723041.0000000001870000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe PID: 5616, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: Process Memory Space: FqJXaFxwEj.exe PID: 4460, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: Process Memory Space: cmd.exe PID: 3628, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_02E34948 0_2_02E34948
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_02E34938 0_2_02E34938
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053506E8 0_2_053506E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053528E0 0_2_053528E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053566F8 0_2_053566F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053566EB 0_2_053566EB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053506D9 0_2_053506D9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_05352330 0_2_05352330
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_05352320 0_2_05352320
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_05356998 0_2_05356998
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_05356989 0_2_05356989
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Code function: 7_2_011DC164 7_2_011DC164
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Code function: 7_2_011DE5B0 7_2_011DE5B0
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Code function: 7_2_011DE5A1 7_2_011DE5A1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B22990 9_2_01B22990
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1C1C0 9_2_01B1C1C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0F900 9_2_01B0F900
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD20A8 9_2_01BD20A8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1B090 9_2_01B1B090
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC60F5 9_2_01BC60F5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD28EC 9_2_01BD28EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A830 9_2_01B2A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BDE824 9_2_01BDE824
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B06800 9_2_01B06800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1002 9_2_01BC1002
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3EBB0 9_2_01B3EBB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2EB9A 9_2_01B2EB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BAEB8A 9_2_01BAEB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3138B 9_2_01B3138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB23E3 9_2_01BB23E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B58BE8 9_2_01B58BE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC03DA 9_2_01BC03DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3ABD8 9_2_01B3ABD8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCDBD2 9_2_01BCDBD2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD2B28 9_2_01BD2B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC231B 9_2_01BC231B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B23360 9_2_01B23360
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2AB40 9_2_01B2AB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BACB4F 9_2_01BACB4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD22AE 9_2_01BD22AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD32A9 9_2_01BD32A9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCE2C5 9_2_01BCE2C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBFA2B 9_2_01BBFA2B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC5A4F 9_2_01BC5A4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B365A0 9_2_01B365A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32581 9_2_01B32581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1D5E0 9_2_01B1D5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD25DD 9_2_01BD25DD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B00D20 9_2_01B00D20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD2D07 9_2_01BD2D07
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B22D50 9_2_01B22D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD1D55 9_2_01BD1D55
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4496 9_2_01BC4496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34CD4 9_2_01B34CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B22430 9_2_01B22430
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1841F 9_2_01B1841F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B477 9_2_01B2B477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCCC77 9_2_01BCCC77
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCD466 9_2_01BCD466
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD1FF1 9_2_01BD1FF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC67E2 9_2_01BC67E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BDDFCE 9_2_01BDDFCE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB1EB6 9_2_01BB1EB6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD2EF7 9_2_01BD2EF7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B306C0 9_2_01B306C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B26E30 9_2_01B26E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCD616 9_2_01BCD616
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B25600 9_2_01B25600
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09660 9_2_01B09660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B8AE60 9_2_01B8AE60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004012A3 9_2_004012A3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0042195E 9_2_0042195E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00422343 9_2_00422343
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004223DC 9_2_004223DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00422C0F 9_2_00422C0F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004044C7 9_2_004044C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004044BE 9_2_004044BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0040B532 9_2_0040B532
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0040B537 9_2_0040B537
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004225D3 9_2_004225D3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0042159C 9_2_0042159C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: String function: 01B95720 appears 85 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: String function: 01B5D08C appears 48 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: String function: 01B0B150 appears 177 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49860 NtQuerySystemInformation,LdrInitializeThunk, 9_2_01B49860
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B496E0 NtFreeVirtualMemory,LdrInitializeThunk, 9_2_01B496E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49660 NtAllocateVirtualMemory,LdrInitializeThunk, 9_2_01B49660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B499A0 NtCreateSection, 9_2_01B499A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B499D0 NtCreateProcessEx, 9_2_01B499D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49910 NtAdjustPrivilegesToken, 9_2_01B49910
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49950 NtQueueApcThread, 9_2_01B49950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B498A0 NtWriteVirtualMemory, 9_2_01B498A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B498F0 NtReadVirtualMemory, 9_2_01B498F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49820 NtEnumerateKey, 9_2_01B49820
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49840 NtDelayExecution, 9_2_01B49840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4B040 NtSuspendThread, 9_2_01B4B040
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4A3B0 NtGetContextThread, 9_2_01B4A3B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49B00 NtSetValueKey, 9_2_01B49B00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49A80 NtOpenDirectoryObject, 9_2_01B49A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49A20 NtResumeThread, 9_2_01B49A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49A10 NtQuerySection, 9_2_01B49A10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49A00 NtProtectVirtualMemory, 9_2_01B49A00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49A50 NtCreateFile, 9_2_01B49A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B495F0 NtQueryInformationFile, 9_2_01B495F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B495D0 NtClose, 9_2_01B495D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4AD30 NtSetContextThread, 9_2_01B4AD30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49520 NtWaitForSingleObject, 9_2_01B49520
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49560 NtWriteFile, 9_2_01B49560
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49540 NtReadFile, 9_2_01B49540
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B497A0 NtUnmapViewOfSection, 9_2_01B497A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49780 NtMapViewOfSection, 9_2_01B49780
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49FE0 NtCreateMutant, 9_2_01B49FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49730 NtQueryVirtualMemory, 9_2_01B49730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49710 NtQueryInformationToken, 9_2_01B49710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4A710 NtOpenProcessToken, 9_2_01B4A710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49770 NtSetInformationFile, 9_2_01B49770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4A770 NtOpenThread, 9_2_01B4A770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49760 NtOpenProcess, 9_2_01B49760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B496D0 NtCreateKey, 9_2_01B496D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49610 NtEnumerateValueKey, 9_2_01B49610
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49670 NtQueryInformationProcess, 9_2_01B49670
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49650 NtQueryValueKey, 9_2_01B49650
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E047 NtReadFile, 9_2_0041E047
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E0C7 NtClose, 9_2_0041E0C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E177 NtAllocateVirtualMemory, 9_2_0041E177
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004012A3 NtProtectVirtualMemory, 9_2_004012A3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041DF97 NtCreateFile, 9_2_0041DF97
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E042 NtReadFile, 9_2_0041E042
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E0C1 NtClose, 9_2_0041E0C1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041E173 NtAllocateVirtualMemory, 9_2_0041E173
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004014E9 NtProtectVirtualMemory, 9_2_004014E9
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePrecision.dll6 vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameInspector.dllN vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000000.308286342.0000000000A42000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamenXwV.exeB vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.366984387.0000000007650000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameCollins.dll8 vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.360162279.0000000001A69000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.357988306.00000000018BD000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000002.362197036.0000000001BFF000.00000040.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Binary or memory string: OriginalFilenamenXwV.exeB vs SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: FqJXaFxwEj.exe.0.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe ReversingLabs: Detection: 29%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp4724.tmp
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp8C7A.tmp
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe
Source: C:\Windows\explorer.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp4724.tmp Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp8C7A.tmp Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File created: C:\Users\user\AppData\Local\Temp\tmp4724.tmp Jump to behavior
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@21/12@2/1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000000.308136610.0000000000962000.00000002.00000001.01000000.00000003.sdmp, FqJXaFxwEj.exe.0.dr Binary or memory string: insert into User_Transportation(UserID,TransportationID) values (@UserID,@TransID);
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000000.308136610.0000000000962000.00000002.00000001.01000000.00000003.sdmp, FqJXaFxwEj.exe.0.dr Binary or memory string: insert into TourPlace(Name,Location,TicketPrice) values (@name,@location,@ticket);
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000000.308136610.0000000000962000.00000002.00000001.01000000.00000003.sdmp, FqJXaFxwEj.exe.0.dr Binary or memory string: insert into User_TourPlace(UserID,TourPlaceID) values (@UserID,@TourplaceID);
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5212:120:WilError_01
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1028:120:WilError_01
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3216:120:WilError_01
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Mutant created: \Sessions\1\BaseNamedObjects\FgAniyuUJLIlHUpU
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5072:120:WilError_01
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe String found in binary or memory: AddUserButton'AddUserPhoneTextbox'AdduserEmailtextbox-Adduserpasswordtextbox
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe String found in binary or memory: Username:-AddusertextBoxUsernameCash
Source: C:\Windows\explorer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\explorer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.359410400.000000000194A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000002.361323624.0000000001AE0000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.355211610.00000000017A7000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 0000000D.00000002.501948554.0000000001950000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.504620671.0000000003588000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.578060777.0000000003720000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.501310955.00000000033F0000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.581625002.000000000383F000.00000040.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.359410400.000000000194A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000002.361323624.0000000001AE0000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000009.00000003.355211610.00000000017A7000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 0000000D.00000002.501948554.0000000001950000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.504620671.0000000003588000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.578060777.0000000003720000.00000040.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000003.501310955.00000000033F0000.00000004.00000800.00020000.00000000.sdmp, cmd.exe, 00000011.00000002.581625002.000000000383F000.00000040.00000800.00020000.00000000.sdmp
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_02E3F401 push ecx; ret 0_2_02E3F415
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 0_2_053571C1 push esp; iretd 0_2_053571C2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B5D0D1 push ecx; ret 9_2_01B5D0E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0040588C push 00000021h; retf 9_2_0040588E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004229DB push ebx; ret 9_2_004229DF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_004212CC push eax; ret 9_2_0042131F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00421319 push eax; ret 9_2_0042131F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00421322 push eax; ret 9_2_00421389
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00421383 push eax; ret 9_2_00421389
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00409C01 push eax; iretd 9_2_00409C1B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_00422C0F push dword ptr [B99DF5C4h]; ret 9_2_00422FF5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_0041AD57 push ebp; iretd 9_2_0041AD5B
Source: initial sample Static PE information: section name: .text entropy: 7.644411619658559
Source: initial sample Static PE information: section name: .text entropy: 7.644411619658559
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe File created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp4724.tmp
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: Yara match File source: 7.2.FqJXaFxwEj.exe.2e02e38.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.FqJXaFxwEj.exe.2e20608.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2eb0724.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe.2e92f54.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.390890604.00000000030C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.361866159.0000000003151000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe PID: 3292, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: FqJXaFxwEj.exe PID: 5516, type: MEMORYSTR
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.361866159.0000000003151000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.390890604.00000000030C0000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SBIEDLL.DLL
Source: SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.359675878.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe, 00000000.00000002.361866159.0000000003151000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.390890604.00000000030C0000.00000004.00000800.00020000.00000000.sdmp, FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe TID: 4584 Thread sleep time: -38122s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe TID: 2144 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2264 Thread sleep time: -6456360425798339s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5192 Thread sleep count: 9277 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 996 Thread sleep time: -5534023222112862s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe TID: 5560 Thread sleep time: -38122s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe TID: 2472 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\explorer.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD5BA5 rdtsc 9_2_01BD5BA5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 9438 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 9277 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe API coverage: 1.2 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Thread delayed: delay time: 38122 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Thread delayed: delay time: 38122 Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: explorer.exe, 0000000E.00000000.411916320.000000000834F000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&0000006
Source: explorer.exe, 0000000E.00000000.454651139.000000000830B000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000
Source: explorer.exe, 0000000E.00000000.400286007.00000000059F0000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}b
Source: FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: explorer.exe, 0000000E.00000000.455182068.0000000008394000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmware
Source: explorer.exe, 0000000E.00000000.486557090.000000000CDEC000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: _VMware_SATA_CD00#5&
Source: explorer.exe, 0000000E.00000000.454651139.000000000830B000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&0000000
Source: explorer.exe, 0000000E.00000000.415035418.00000000085A9000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: #CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware SVGA II
Source: FqJXaFxwEj.exe, 00000007.00000002.388062952.0000000002DE1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD5BA5 rdtsc 9_2_01BD5BA5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B851BE mov eax, dword ptr fs:[00000030h] 9_2_01B851BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B851BE mov eax, dword ptr fs:[00000030h] 9_2_01B851BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B851BE mov eax, dword ptr fs:[00000030h] 9_2_01B851BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B851BE mov eax, dword ptr fs:[00000030h] 9_2_01B851BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BDF1B5 mov eax, dword ptr fs:[00000030h] 9_2_01BDF1B5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BDF1B5 mov eax, dword ptr fs:[00000030h] 9_2_01BDF1B5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3C9BF mov eax, dword ptr fs:[00000030h] 9_2_01B3C9BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3C9BF mov eax, dword ptr fs:[00000030h] 9_2_01B3C9BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov eax, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov eax, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov eax, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov ecx, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B299BF mov eax, dword ptr fs:[00000030h] 9_2_01B299BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B399BC mov eax, dword ptr fs:[00000030h] 9_2_01B399BC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B361A0 mov eax, dword ptr fs:[00000030h] 9_2_01B361A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B361A0 mov eax, dword ptr fs:[00000030h] 9_2_01B361A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B161A7 mov eax, dword ptr fs:[00000030h] 9_2_01B161A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B161A7 mov eax, dword ptr fs:[00000030h] 9_2_01B161A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B161A7 mov eax, dword ptr fs:[00000030h] 9_2_01B161A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B161A7 mov eax, dword ptr fs:[00000030h] 9_2_01B161A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC49A4 mov eax, dword ptr fs:[00000030h] 9_2_01BC49A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC49A4 mov eax, dword ptr fs:[00000030h] 9_2_01BC49A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC49A4 mov eax, dword ptr fs:[00000030h] 9_2_01BC49A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC49A4 mov eax, dword ptr fs:[00000030h] 9_2_01BC49A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B869A6 mov eax, dword ptr fs:[00000030h] 9_2_01B869A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B08190 mov ecx, dword ptr fs:[00000030h] 9_2_01B08190
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32990 mov eax, dword ptr fs:[00000030h] 9_2_01B32990
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34190 mov eax, dword ptr fs:[00000030h] 9_2_01B34190
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0519E mov eax, dword ptr fs:[00000030h] 9_2_01B0519E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0519E mov ecx, dword ptr fs:[00000030h] 9_2_01B0519E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2C182 mov eax, dword ptr fs:[00000030h] 9_2_01B2C182
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCA189 mov eax, dword ptr fs:[00000030h] 9_2_01BCA189
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCA189 mov ecx, dword ptr fs:[00000030h] 9_2_01BCA189
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3A185 mov eax, dword ptr fs:[00000030h] 9_2_01B3A185
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B031E0 mov eax, dword ptr fs:[00000030h] 9_2_01B031E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B941E8 mov eax, dword ptr fs:[00000030h] 9_2_01B941E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0B1E1 mov eax, dword ptr fs:[00000030h] 9_2_01B0B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0B1E1 mov eax, dword ptr fs:[00000030h] 9_2_01B0B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0B1E1 mov eax, dword ptr fs:[00000030h] 9_2_01B0B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD89E7 mov eax, dword ptr fs:[00000030h] 9_2_01BD89E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2D1EF mov eax, dword ptr fs:[00000030h] 9_2_01B2D1EF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov ecx, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov ecx, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC31DC mov eax, dword ptr fs:[00000030h] 9_2_01BC31DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC19D8 mov eax, dword ptr fs:[00000030h] 9_2_01BC19D8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1C1C0 mov eax, dword ptr fs:[00000030h] 9_2_01B1C1C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B199C7 mov eax, dword ptr fs:[00000030h] 9_2_01B199C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B199C7 mov eax, dword ptr fs:[00000030h] 9_2_01B199C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B199C7 mov eax, dword ptr fs:[00000030h] 9_2_01B199C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B199C7 mov eax, dword ptr fs:[00000030h] 9_2_01B199C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B03138 mov ecx, dword ptr fs:[00000030h] 9_2_01B03138
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3513A mov eax, dword ptr fs:[00000030h] 9_2_01B3513A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3513A mov eax, dword ptr fs:[00000030h] 9_2_01B3513A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 mov eax, dword ptr fs:[00000030h] 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 mov eax, dword ptr fs:[00000030h] 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 mov eax, dword ptr fs:[00000030h] 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 mov eax, dword ptr fs:[00000030h] 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B24120 mov ecx, dword ptr fs:[00000030h] 9_2_01B24120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09100 mov eax, dword ptr fs:[00000030h] 9_2_01B09100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09100 mov eax, dword ptr fs:[00000030h] 9_2_01B09100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09100 mov eax, dword ptr fs:[00000030h] 9_2_01B09100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B10100 mov eax, dword ptr fs:[00000030h] 9_2_01B10100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B10100 mov eax, dword ptr fs:[00000030h] 9_2_01B10100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B10100 mov eax, dword ptr fs:[00000030h] 9_2_01B10100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0B171 mov eax, dword ptr fs:[00000030h] 9_2_01B0B171
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0B171 mov eax, dword ptr fs:[00000030h] 9_2_01B0B171
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0C962 mov eax, dword ptr fs:[00000030h] 9_2_01B0C962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8966 mov eax, dword ptr fs:[00000030h] 9_2_01BD8966
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCE962 mov eax, dword ptr fs:[00000030h] 9_2_01BCE962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1951 mov eax, dword ptr fs:[00000030h] 9_2_01BC1951
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0395E mov eax, dword ptr fs:[00000030h] 9_2_01B0395E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0395E mov eax, dword ptr fs:[00000030h] 9_2_01B0395E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B944 mov eax, dword ptr fs:[00000030h] 9_2_01B2B944
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B944 mov eax, dword ptr fs:[00000030h] 9_2_01B2B944
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F0BF mov ecx, dword ptr fs:[00000030h] 9_2_01B3F0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F0BF mov eax, dword ptr fs:[00000030h] 9_2_01B3F0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F0BF mov eax, dword ptr fs:[00000030h] 9_2_01B3F0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B320A0 mov eax, dword ptr fs:[00000030h] 9_2_01B320A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B378A0 mov eax, dword ptr fs:[00000030h] 9_2_01B378A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B490AF mov eax, dword ptr fs:[00000030h] 9_2_01B490AF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov eax, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov eax, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov eax, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov ecx, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov eax, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128AE mov eax, dword ptr fs:[00000030h] 9_2_01B128AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09080 mov eax, dword ptr fs:[00000030h] 9_2_01B09080
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B03880 mov eax, dword ptr fs:[00000030h] 9_2_01B03880
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B03880 mov eax, dword ptr fs:[00000030h] 9_2_01B03880
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B83884 mov eax, dword ptr fs:[00000030h] 9_2_01B83884
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B83884 mov eax, dword ptr fs:[00000030h] 9_2_01B83884
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC60F5 mov eax, dword ptr fs:[00000030h] 9_2_01BC60F5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC60F5 mov eax, dword ptr fs:[00000030h] 9_2_01BC60F5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC60F5 mov eax, dword ptr fs:[00000030h] 9_2_01BC60F5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC60F5 mov eax, dword ptr fs:[00000030h] 9_2_01BC60F5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128FD mov eax, dword ptr fs:[00000030h] 9_2_01B128FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128FD mov eax, dword ptr fs:[00000030h] 9_2_01B128FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B128FD mov eax, dword ptr fs:[00000030h] 9_2_01B128FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B088E0 mov eax, dword ptr fs:[00000030h] 9_2_01B088E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B040E1 mov eax, dword ptr fs:[00000030h] 9_2_01B040E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B040E1 mov eax, dword ptr fs:[00000030h] 9_2_01B040E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B040E1 mov eax, dword ptr fs:[00000030h] 9_2_01B040E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B8E4 mov eax, dword ptr fs:[00000030h] 9_2_01B2B8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B8E4 mov eax, dword ptr fs:[00000030h] 9_2_01B2B8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B058EC mov eax, dword ptr fs:[00000030h] 9_2_01B058EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B078D6 mov eax, dword ptr fs:[00000030h] 9_2_01B078D6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B078D6 mov eax, dword ptr fs:[00000030h] 9_2_01B078D6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B078D6 mov ecx, dword ptr fs:[00000030h] 9_2_01B078D6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov eax, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov ecx, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov eax, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov eax, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov eax, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B9B8D0 mov eax, dword ptr fs:[00000030h] 9_2_01B9B8D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B070C0 mov eax, dword ptr fs:[00000030h] 9_2_01B070C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B070C0 mov eax, dword ptr fs:[00000030h] 9_2_01B070C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC18CA mov eax, dword ptr fs:[00000030h] 9_2_01BC18CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB0C7 mov eax, dword ptr fs:[00000030h] 9_2_01BCB0C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB0C7 mov eax, dword ptr fs:[00000030h] 9_2_01BCB0C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A830 mov eax, dword ptr fs:[00000030h] 9_2_01B2A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A830 mov eax, dword ptr fs:[00000030h] 9_2_01B2A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A830 mov eax, dword ptr fs:[00000030h] 9_2_01B2A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A830 mov eax, dword ptr fs:[00000030h] 9_2_01B2A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34020 mov edi, dword ptr fs:[00000030h] 9_2_01B34020
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1B02A mov eax, dword ptr fs:[00000030h] 9_2_01B1B02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1B02A mov eax, dword ptr fs:[00000030h] 9_2_01B1B02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1B02A mov eax, dword ptr fs:[00000030h] 9_2_01B1B02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1B02A mov eax, dword ptr fs:[00000030h] 9_2_01B1B02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3002D mov eax, dword ptr fs:[00000030h] 9_2_01B3002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3002D mov eax, dword ptr fs:[00000030h] 9_2_01B3002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3002D mov eax, dword ptr fs:[00000030h] 9_2_01B3002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3002D mov eax, dword ptr fs:[00000030h] 9_2_01B3002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3002D mov eax, dword ptr fs:[00000030h] 9_2_01B3002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD4015 mov eax, dword ptr fs:[00000030h] 9_2_01BD4015
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD4015 mov eax, dword ptr fs:[00000030h] 9_2_01BD4015
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B87016 mov eax, dword ptr fs:[00000030h] 9_2_01B87016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B87016 mov eax, dword ptr fs:[00000030h] 9_2_01B87016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B87016 mov eax, dword ptr fs:[00000030h] 9_2_01B87016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3701D mov eax, dword ptr fs:[00000030h] 9_2_01B3701D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B06800 mov eax, dword ptr fs:[00000030h] 9_2_01B06800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B06800 mov eax, dword ptr fs:[00000030h] 9_2_01B06800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B06800 mov eax, dword ptr fs:[00000030h] 9_2_01B06800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD1074 mov eax, dword ptr fs:[00000030h] 9_2_01BD1074
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2073 mov eax, dword ptr fs:[00000030h] 9_2_01BC2073
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2F86D mov eax, dword ptr fs:[00000030h] 9_2_01B2F86D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05050 mov eax, dword ptr fs:[00000030h] 9_2_01B05050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05050 mov eax, dword ptr fs:[00000030h] 9_2_01B05050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05050 mov eax, dword ptr fs:[00000030h] 9_2_01B05050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B07057 mov eax, dword ptr fs:[00000030h] 9_2_01B07057
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1843 mov eax, dword ptr fs:[00000030h] 9_2_01BC1843
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD9BBE mov eax, dword ptr fs:[00000030h] 9_2_01BD9BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8BB6 mov eax, dword ptr fs:[00000030h] 9_2_01BD8BB6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1BA8 mov eax, dword ptr fs:[00000030h] 9_2_01BC1BA8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD5BA5 mov eax, dword ptr fs:[00000030h] 9_2_01BD5BA5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34BAD mov eax, dword ptr fs:[00000030h] 9_2_01B34BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34BAD mov eax, dword ptr fs:[00000030h] 9_2_01B34BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34BAD mov eax, dword ptr fs:[00000030h] 9_2_01B34BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3B390 mov eax, dword ptr fs:[00000030h] 9_2_01B3B390
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32397 mov eax, dword ptr fs:[00000030h] 9_2_01B32397
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B04B94 mov edi, dword ptr fs:[00000030h] 9_2_01B04B94
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2EB9A mov eax, dword ptr fs:[00000030h] 9_2_01B2EB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2EB9A mov eax, dword ptr fs:[00000030h] 9_2_01B2EB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BAEB8A mov ecx, dword ptr fs:[00000030h] 9_2_01BAEB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BAEB8A mov eax, dword ptr fs:[00000030h] 9_2_01BAEB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BAEB8A mov eax, dword ptr fs:[00000030h] 9_2_01BAEB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BAEB8A mov eax, dword ptr fs:[00000030h] 9_2_01BAEB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC138A mov eax, dword ptr fs:[00000030h] 9_2_01BC138A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3138B mov eax, dword ptr fs:[00000030h] 9_2_01B3138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3138B mov eax, dword ptr fs:[00000030h] 9_2_01B3138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3138B mov eax, dword ptr fs:[00000030h] 9_2_01B3138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBD380 mov ecx, dword ptr fs:[00000030h] 9_2_01BBD380
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B11B8F mov eax, dword ptr fs:[00000030h] 9_2_01B11B8F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B11B8F mov eax, dword ptr fs:[00000030h] 9_2_01B11B8F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B303E2 mov eax, dword ptr fs:[00000030h] 9_2_01B303E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BA6BEC mov eax, dword ptr fs:[00000030h] 9_2_01BA6BEC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BA6BEC mov eax, dword ptr fs:[00000030h] 9_2_01BA6BEC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BA6BEC mov eax, dword ptr fs:[00000030h] 9_2_01BA6BEC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB23E3 mov ecx, dword ptr fs:[00000030h] 9_2_01BB23E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB23E3 mov ecx, dword ptr fs:[00000030h] 9_2_01BB23E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB23E3 mov eax, dword ptr fs:[00000030h] 9_2_01BB23E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B01BE9 mov eax, dword ptr fs:[00000030h] 9_2_01B01BE9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2DBE9 mov eax, dword ptr fs:[00000030h] 9_2_01B2DBE9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B853CA mov eax, dword ptr fs:[00000030h] 9_2_01B853CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B853CA mov eax, dword ptr fs:[00000030h] 9_2_01B853CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B353C5 mov eax, dword ptr fs:[00000030h] 9_2_01B353C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC131B mov eax, dword ptr fs:[00000030h] 9_2_01BC131B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A309 mov eax, dword ptr fs:[00000030h] 9_2_01B2A309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B07B70 mov eax, dword ptr fs:[00000030h] 9_2_01B07B70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1F370 mov eax, dword ptr fs:[00000030h] 9_2_01B1F370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1F370 mov eax, dword ptr fs:[00000030h] 9_2_01B1F370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1F370 mov eax, dword ptr fs:[00000030h] 9_2_01B1F370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B7A mov eax, dword ptr fs:[00000030h] 9_2_01B33B7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B7A mov eax, dword ptr fs:[00000030h] 9_2_01B33B7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0DB60 mov ecx, dword ptr fs:[00000030h] 9_2_01B0DB60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B96365 mov eax, dword ptr fs:[00000030h] 9_2_01B96365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B96365 mov eax, dword ptr fs:[00000030h] 9_2_01B96365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B96365 mov eax, dword ptr fs:[00000030h] 9_2_01B96365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8B58 mov eax, dword ptr fs:[00000030h] 9_2_01BD8B58
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0F358 mov eax, dword ptr fs:[00000030h] 9_2_01B0F358
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B5A mov eax, dword ptr fs:[00000030h] 9_2_01B33B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B5A mov eax, dword ptr fs:[00000030h] 9_2_01B33B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B5A mov eax, dword ptr fs:[00000030h] 9_2_01B33B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B33B5A mov eax, dword ptr fs:[00000030h] 9_2_01B33B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0DB40 mov eax, dword ptr fs:[00000030h] 9_2_01B0DB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1AAB0 mov eax, dword ptr fs:[00000030h] 9_2_01B1AAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1AAB0 mov eax, dword ptr fs:[00000030h] 9_2_01B1AAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3FAB0 mov eax, dword ptr fs:[00000030h] 9_2_01B3FAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B312BD mov esi, dword ptr fs:[00000030h] 9_2_01B312BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B312BD mov eax, dword ptr fs:[00000030h] 9_2_01B312BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B312BD mov eax, dword ptr fs:[00000030h] 9_2_01B312BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B01AA0 mov eax, dword ptr fs:[00000030h] 9_2_01B01AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B162A0 mov eax, dword ptr fs:[00000030h] 9_2_01B162A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B162A0 mov eax, dword ptr fs:[00000030h] 9_2_01B162A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B162A0 mov eax, dword ptr fs:[00000030h] 9_2_01B162A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B162A0 mov eax, dword ptr fs:[00000030h] 9_2_01B162A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B35AA0 mov eax, dword ptr fs:[00000030h] 9_2_01B35AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B35AA0 mov eax, dword ptr fs:[00000030h] 9_2_01B35AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B052A5 mov eax, dword ptr fs:[00000030h] 9_2_01B052A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B052A5 mov eax, dword ptr fs:[00000030h] 9_2_01B052A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B052A5 mov eax, dword ptr fs:[00000030h] 9_2_01B052A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B052A5 mov eax, dword ptr fs:[00000030h] 9_2_01B052A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B052A5 mov eax, dword ptr fs:[00000030h] 9_2_01B052A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC129A mov eax, dword ptr fs:[00000030h] 9_2_01BC129A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3D294 mov eax, dword ptr fs:[00000030h] 9_2_01B3D294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3D294 mov eax, dword ptr fs:[00000030h] 9_2_01B3D294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3DA88 mov eax, dword ptr fs:[00000030h] 9_2_01B3DA88
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3DA88 mov eax, dword ptr fs:[00000030h] 9_2_01B3DA88
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC4AEF mov eax, dword ptr fs:[00000030h] 9_2_01BC4AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB2E8 mov eax, dword ptr fs:[00000030h] 9_2_01BCB2E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB2E8 mov eax, dword ptr fs:[00000030h] 9_2_01BCB2E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB2E8 mov eax, dword ptr fs:[00000030h] 9_2_01BCB2E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB2E8 mov eax, dword ptr fs:[00000030h] 9_2_01BCB2E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32AE4 mov eax, dword ptr fs:[00000030h] 9_2_01B32AE4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8ADD mov eax, dword ptr fs:[00000030h] 9_2_01BD8ADD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B012D4 mov eax, dword ptr fs:[00000030h] 9_2_01B012D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05AC0 mov eax, dword ptr fs:[00000030h] 9_2_01B05AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05AC0 mov eax, dword ptr fs:[00000030h] 9_2_01B05AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05AC0 mov eax, dword ptr fs:[00000030h] 9_2_01B05AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32ACB mov eax, dword ptr fs:[00000030h] 9_2_01B32ACB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B03ACA mov eax, dword ptr fs:[00000030h] 9_2_01B03ACA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2B236 mov eax, dword ptr fs:[00000030h] 9_2_01B2B236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B08239 mov eax, dword ptr fs:[00000030h] 9_2_01B08239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B08239 mov eax, dword ptr fs:[00000030h] 9_2_01B08239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B08239 mov eax, dword ptr fs:[00000030h] 9_2_01B08239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B04A20 mov eax, dword ptr fs:[00000030h] 9_2_01B04A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B04A20 mov eax, dword ptr fs:[00000030h] 9_2_01B04A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1229 mov eax, dword ptr fs:[00000030h] 9_2_01BC1229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B44A2C mov eax, dword ptr fs:[00000030h] 9_2_01B44A2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B44A2C mov eax, dword ptr fs:[00000030h] 9_2_01B44A2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2A229 mov eax, dword ptr fs:[00000030h] 9_2_01B2A229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05210 mov eax, dword ptr fs:[00000030h] 9_2_01B05210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05210 mov ecx, dword ptr fs:[00000030h] 9_2_01B05210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05210 mov eax, dword ptr fs:[00000030h] 9_2_01B05210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B05210 mov eax, dword ptr fs:[00000030h] 9_2_01B05210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0AA16 mov eax, dword ptr fs:[00000030h] 9_2_01B0AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0AA16 mov eax, dword ptr fs:[00000030h] 9_2_01B0AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCAA16 mov eax, dword ptr fs:[00000030h] 9_2_01BCAA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCAA16 mov eax, dword ptr fs:[00000030h] 9_2_01BCAA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B23A1C mov eax, dword ptr fs:[00000030h] 9_2_01B23A1C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov ecx, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1BA00 mov eax, dword ptr fs:[00000030h] 9_2_01B1BA00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B18A0A mov eax, dword ptr fs:[00000030h] 9_2_01B18A0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B4927A mov eax, dword ptr fs:[00000030h] 9_2_01B4927A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBB260 mov eax, dword ptr fs:[00000030h] 9_2_01BBB260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBB260 mov eax, dword ptr fs:[00000030h] 9_2_01BBB260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B45A69 mov eax, dword ptr fs:[00000030h] 9_2_01B45A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B45A69 mov eax, dword ptr fs:[00000030h] 9_2_01B45A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B45A69 mov eax, dword ptr fs:[00000030h] 9_2_01B45A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8A62 mov eax, dword ptr fs:[00000030h] 9_2_01BD8A62
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC1A5F mov eax, dword ptr fs:[00000030h] 9_2_01BC1A5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCEA55 mov eax, dword ptr fs:[00000030h] 9_2_01BCEA55
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B94257 mov eax, dword ptr fs:[00000030h] 9_2_01B94257
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09240 mov eax, dword ptr fs:[00000030h] 9_2_01B09240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09240 mov eax, dword ptr fs:[00000030h] 9_2_01B09240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09240 mov eax, dword ptr fs:[00000030h] 9_2_01B09240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09240 mov eax, dword ptr fs:[00000030h] 9_2_01B09240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC5A4F mov eax, dword ptr fs:[00000030h] 9_2_01BC5A4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC5A4F mov eax, dword ptr fs:[00000030h] 9_2_01BC5A4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC5A4F mov eax, dword ptr fs:[00000030h] 9_2_01BC5A4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC5A4F mov eax, dword ptr fs:[00000030h] 9_2_01BC5A4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B31DB5 mov eax, dword ptr fs:[00000030h] 9_2_01B31DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B31DB5 mov eax, dword ptr fs:[00000030h] 9_2_01B31DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B31DB5 mov eax, dword ptr fs:[00000030h] 9_2_01B31DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B45DBF mov eax, dword ptr fs:[00000030h] 9_2_01B45DBF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B45DBF mov eax, dword ptr fs:[00000030h] 9_2_01B45DBF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD05AC mov eax, dword ptr fs:[00000030h] 9_2_01BD05AC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD05AC mov eax, dword ptr fs:[00000030h] 9_2_01BD05AC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B335A1 mov eax, dword ptr fs:[00000030h] 9_2_01B335A1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B365A0 mov eax, dword ptr fs:[00000030h] 9_2_01B365A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B365A0 mov eax, dword ptr fs:[00000030h] 9_2_01B365A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B365A0 mov eax, dword ptr fs:[00000030h] 9_2_01B365A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B03591 mov eax, dword ptr fs:[00000030h] 9_2_01B03591
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3FD9B mov eax, dword ptr fs:[00000030h] 9_2_01B3FD9B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3FD9B mov eax, dword ptr fs:[00000030h] 9_2_01B3FD9B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32581 mov eax, dword ptr fs:[00000030h] 9_2_01B32581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32581 mov eax, dword ptr fs:[00000030h] 9_2_01B32581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32581 mov eax, dword ptr fs:[00000030h] 9_2_01B32581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B32581 mov eax, dword ptr fs:[00000030h] 9_2_01B32581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B02D8A mov eax, dword ptr fs:[00000030h] 9_2_01B02D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B02D8A mov eax, dword ptr fs:[00000030h] 9_2_01B02D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B02D8A mov eax, dword ptr fs:[00000030h] 9_2_01B02D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B02D8A mov eax, dword ptr fs:[00000030h] 9_2_01B02D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B02D8A mov eax, dword ptr fs:[00000030h] 9_2_01B02D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB581 mov eax, dword ptr fs:[00000030h] 9_2_01BCB581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB581 mov eax, dword ptr fs:[00000030h] 9_2_01BCB581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB581 mov eax, dword ptr fs:[00000030h] 9_2_01BCB581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCB581 mov eax, dword ptr fs:[00000030h] 9_2_01BCB581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC2D82 mov eax, dword ptr fs:[00000030h] 9_2_01BC2D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B095F0 mov eax, dword ptr fs:[00000030h] 9_2_01B095F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B095F0 mov ecx, dword ptr fs:[00000030h] 9_2_01B095F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB8DF1 mov eax, dword ptr fs:[00000030h] 9_2_01BB8DF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1D5E0 mov eax, dword ptr fs:[00000030h] 9_2_01B1D5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B1D5E0 mov eax, dword ptr fs:[00000030h] 9_2_01B1D5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B93DE3 mov ecx, dword ptr fs:[00000030h] 9_2_01B93DE3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B93DE3 mov eax, dword ptr fs:[00000030h] 9_2_01B93DE3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B93DE3 mov eax, dword ptr fs:[00000030h] 9_2_01B93DE3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCFDE2 mov eax, dword ptr fs:[00000030h] 9_2_01BCFDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCFDE2 mov eax, dword ptr fs:[00000030h] 9_2_01BCFDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCFDE2 mov eax, dword ptr fs:[00000030h] 9_2_01BCFDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCFDE2 mov eax, dword ptr fs:[00000030h] 9_2_01BCFDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B395EC mov eax, dword ptr fs:[00000030h] 9_2_01B395EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBFDD3 mov eax, dword ptr fs:[00000030h] 9_2_01BBFDD3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov eax, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov eax, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov eax, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov ecx, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov eax, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B86DC9 mov eax, dword ptr fs:[00000030h] 9_2_01B86DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B015C1 mov eax, dword ptr fs:[00000030h] 9_2_01B015C1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0AD30 mov eax, dword ptr fs:[00000030h] 9_2_01B0AD30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B13D34 mov eax, dword ptr fs:[00000030h] 9_2_01B13D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BCE539 mov eax, dword ptr fs:[00000030h] 9_2_01BCE539
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34D3B mov eax, dword ptr fs:[00000030h] 9_2_01B34D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34D3B mov eax, dword ptr fs:[00000030h] 9_2_01B34D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B34D3B mov eax, dword ptr fs:[00000030h] 9_2_01B34D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD8D34 mov eax, dword ptr fs:[00000030h] 9_2_01BD8D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B8A537 mov eax, dword ptr fs:[00000030h] 9_2_01B8A537
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F527 mov eax, dword ptr fs:[00000030h] 9_2_01B3F527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F527 mov eax, dword ptr fs:[00000030h] 9_2_01B3F527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3F527 mov eax, dword ptr fs:[00000030h] 9_2_01B3F527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC3518 mov eax, dword ptr fs:[00000030h] 9_2_01BC3518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC3518 mov eax, dword ptr fs:[00000030h] 9_2_01BC3518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BC3518 mov eax, dword ptr fs:[00000030h] 9_2_01BC3518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B09515 mov ecx, dword ptr fs:[00000030h] 9_2_01B09515
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0751A mov eax, dword ptr fs:[00000030h] 9_2_01B0751A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0751A mov eax, dword ptr fs:[00000030h] 9_2_01B0751A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0751A mov eax, dword ptr fs:[00000030h] 9_2_01B0751A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0751A mov eax, dword ptr fs:[00000030h] 9_2_01B0751A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BACD04 mov eax, dword ptr fs:[00000030h] 9_2_01BACD04
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B28D76 mov eax, dword ptr fs:[00000030h] 9_2_01B28D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B28D76 mov eax, dword ptr fs:[00000030h] 9_2_01B28D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B28D76 mov eax, dword ptr fs:[00000030h] 9_2_01B28D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B28D76 mov eax, dword ptr fs:[00000030h] 9_2_01B28D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B28D76 mov eax, dword ptr fs:[00000030h] 9_2_01B28D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2C577 mov eax, dword ptr fs:[00000030h] 9_2_01B2C577
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B2C577 mov eax, dword ptr fs:[00000030h] 9_2_01B2C577
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B27D50 mov eax, dword ptr fs:[00000030h] 9_2_01B27D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B44D51 mov eax, dword ptr fs:[00000030h] 9_2_01B44D51
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B44D51 mov eax, dword ptr fs:[00000030h] 9_2_01B44D51
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BBFD52 mov eax, dword ptr fs:[00000030h] 9_2_01BBFD52
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B43D43 mov eax, dword ptr fs:[00000030h] 9_2_01B43D43
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B83540 mov eax, dword ptr fs:[00000030h] 9_2_01B83540
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB3D40 mov eax, dword ptr fs:[00000030h] 9_2_01BB3D40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0354C mov eax, dword ptr fs:[00000030h] 9_2_01B0354C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B0354C mov eax, dword ptr fs:[00000030h] 9_2_01B0354C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BB8D47 mov eax, dword ptr fs:[00000030h] 9_2_01BB8D47
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B04CB0 mov eax, dword ptr fs:[00000030h] 9_2_01B04CB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B134B1 mov eax, dword ptr fs:[00000030h] 9_2_01B134B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B134B1 mov eax, dword ptr fs:[00000030h] 9_2_01B134B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B3D4B0 mov eax, dword ptr fs:[00000030h] 9_2_01B3D4B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B964B5 mov eax, dword ptr fs:[00000030h] 9_2_01B964B5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B964B5 mov eax, dword ptr fs:[00000030h] 9_2_01B964B5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01BD9CB3 mov eax, dword ptr fs:[00000030h] 9_2_01BD9CB3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B114A9 mov eax, dword ptr fs:[00000030h] 9_2_01B114A9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B114A9 mov ecx, dword ptr fs:[00000030h] 9_2_01B114A9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B934A0 mov eax, dword ptr fs:[00000030h] 9_2_01B934A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B934A0 mov eax, dword ptr fs:[00000030h] 9_2_01B934A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B934A0 mov eax, dword ptr fs:[00000030h] 9_2_01B934A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process queried: DebugPort
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Code function: 9_2_01B49860 NtQuerySystemInformation,LdrInitializeThunk, 9_2_01B49860
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\explorer.exe Domain query: www.somethingyourselves.com
Source: C:\Windows\explorer.exe Network Connect: 103.193.185.8 80
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Section unmapped: C:\Windows\SysWOW64\cmd.exe base address: D90000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Section loaded: unknown target: C:\Windows\SysWOW64\cmd.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Section loaded: unknown target: C:\Windows\SysWOW64\cmd.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: read write
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Memory written: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Thread APC queued: target process: C:\Windows\explorer.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Thread register set: target process: 3528 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Thread register set: target process: 3528
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp4724.tmp Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\FqJXaFxwEj" /XML "C:\Users\user\AppData\Local\Temp\tmp8C7A.tmp Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Process created: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Jump to behavior
Source: explorer.exe, 0000000E.00000000.473602299.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.444035794.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.389456185.0000000000E50000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: EProgram Managerzx
Source: explorer.exe, 0000000E.00000000.473602299.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.484036893.000000000834F000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000E.00000000.454888148.000000000834F000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: Shell_TrayWnd
Source: explorer.exe, 0000000E.00000000.473602299.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.444035794.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.389456185.0000000000E50000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progman
Source: explorer.exe, 0000000E.00000000.443354268.00000000009C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000000.388566345.00000000009C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000000.473028657.00000000009C8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Progmanath
Source: explorer.exe, 0000000E.00000000.473602299.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.444035794.0000000000E50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000E.00000000.389456185.0000000000E50000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progmanlock
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-ds-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~en-US~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-ds-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~en-US~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Queries volume information: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\FqJXaFxwEj.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.22126.16591.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: C:\Windows\SysWOW64\cmd.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Local State
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local State
Source: C:\Windows\SysWOW64\cmd.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data

Remote Access Functionality

barindex
Source: Yara match File source: 0000000E.00000000.488142164.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000000.461184066.000000000D8E1000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.573699141.0000000000CF0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.361014158.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574248356.0000000003260000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000011.00000002.574000727.00000000030D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs