Windows Analysis Report
SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe

Overview

General Information

Sample Name: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Analysis ID: 755965
MD5: 7081c4822cf1c7572dd82822b8f27c49
SHA1: 4ee3b6c423b1c9ebf5befbc73d1eef0c576cf026
SHA256: b5330f82f3c5c3f223ae9decd3ebdcd74d1a13d95b1c42bd7b2de4e6c6cb0083
Infos:

Detection

GuLoader
Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected GuLoader
Tries to detect Any.run
Uses 32bit PE files
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Stores files to the Windows start menu directory
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Contains functionality for execution timing, often used to detect debuggers
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
PE / OLE file has an invalid certificate
PE file contains more sections than normal
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality for read data from the clipboard

Classification

AV Detection

barindex
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Virustotal: Detection: 29% Perma Link
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe ReversingLabs: Detection: 19%
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: mshtml.pdb source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39652897969.000000001D5B7000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44194181907.000000001D88D000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44191646427.000000001D760000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39647697379.000000001D40D000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39652897969.000000001D5B7000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44194181907.000000001D88D000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44191646427.000000001D760000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39647697379.000000001D40D000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: mshtml.pdbUGP source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00406555 FindFirstFileW,FindClose, 1_2_00406555
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00405A03 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 1_2_00405A03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0040287E FindFirstFileW, 1_2_0040287E
Source: global traffic HTTP traffic detected: GET /wnioMvShFMvcw54.emz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: www.giliro.comCache-Control: no-cache
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: http://inference.location.live.com11111111-1111-1111-1111-111111111111https://partnernext-inference.
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://s.symcd.com06
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176068670.000000000190C000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176265345.000000000192A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176379660.0000000001936000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.giliro.com/wnioMvShFMvcw54.emz
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176068670.000000000190C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.giliro.com/wnioMvShFMvcw54.emz32w
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176379660.0000000001936000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.giliro.com/wnioMvShFMvcw54.emzG
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176379660.0000000001936000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.giliro.com/wnioMvShFMvcw54.emzV
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: http://www.gopher.ftp://ftp.
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482152594.0000000000626000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd-//W3O//DTD
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39481928947.00000000005F2000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/frameset.dtd
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39481928947.00000000005F2000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: https://d.symcb.com/cps0%
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: https://d.symcb.com/rpa0
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe String found in binary or memory: https://d.symcb.com/rpa0.
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp String found in binary or memory: https://inference.location.live.net/inferenceservice/v21/Pox/GetLocationUsingFingerprinte1e71f6b-214
Source: unknown DNS traffic detected: queries for: www.giliro.com
Source: global traffic HTTP traffic detected: GET /wnioMvShFMvcw54.emz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: www.giliro.comCache-Control: no-cache
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_004054B0 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, 1_2_004054B0
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0040344A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 1_2_0040344A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00404CED 1_2_00404CED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_004068DA 1_2_004068DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03340888 1_2_03340888
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DB33 1_2_0332DB33
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DB35 1_2_0332DB35
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320313 1_2_03320313
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332131F 1_2_0332131F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03341379 1_2_03341379
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0334537A 1_2_0334537A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320F7D 1_2_03320F7D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332036A 1_2_0332036A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320B50 1_2_03320B50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DF54 1_2_0332DF54
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03322355 1_2_03322355
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321B5E 1_2_03321B5E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321F44 1_2_03321F44
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332974A 1_2_0332974A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321FB3 1_2_03321FB3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033223BA 1_2_033223BA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332A7BE 1_2_0332A7BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033217A0 1_2_033217A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DF99 1_2_0332DF99
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332139C 1_2_0332139C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033207F0 1_2_033207F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03343BF1 1_2_03343BF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033293E9 1_2_033293E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329BE9 1_2_03329BE9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033207D1 1_2_033207D1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033203DF 1_2_033203DF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332AFDC 1_2_0332AFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329BC1 1_2_03329BC1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0334162E 1_2_0334162E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320614 1_2_03320614
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332221F 1_2_0332221F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321E00 1_2_03321E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320277 1_2_03320277
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03342671 1_2_03342671
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320A63 1_2_03320A63
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320E63 1_2_03320E63
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321A63 1_2_03321A63
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321665 1_2_03321665
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320252 1_2_03320252
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03344256 1_2_03344256
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DE51 1_2_0332DE51
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B254 1_2_0332B254
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321E55 1_2_03321E55
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332AE5C 1_2_0332AE5C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321245 1_2_03321245
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033276B2 1_2_033276B2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033292B4 1_2_033292B4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033212BB 1_2_033212BB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321EBD 1_2_03321EBD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0333FEA9 1_2_0333FEA9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320AF2 1_2_03320AF2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033216F6 1_2_033216F6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DEFF 1_2_0332DEFF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033296E3 1_2_033296E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320ED9 1_2_03320ED9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332AEDC 1_2_0332AEDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033222C5 1_2_033222C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03341EC3 1_2_03341EC3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321537 1_2_03321537
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320535 1_2_03320535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0333F53D 1_2_0333F53D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321929 1_2_03321929
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DD2E 1_2_0332DD2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332E912 1_2_0332E912
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321D1A 1_2_03321D1A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332E11B 1_2_0332E11B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321118 1_2_03321118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329D1D 1_2_03329D1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DD05 1_2_0332DD05
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320D0A 1_2_03320D0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B10C 1_2_0332B10C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321D74 1_2_03321D74
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320175 1_2_03320175
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332257A 1_2_0332257A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329178 1_2_03329178
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03322160 1_2_03322160
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320957 1_2_03320957
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332A154 1_2_0332A154
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320DB0 1_2_03320DB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033205A3 1_2_033205A3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0333C1AB 1_2_0333C1AB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033211AC 1_2_033211AC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320192 1_2_03320192
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321995 1_2_03321995
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332A19A 1_2_0332A19A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332E186 1_2_0332E186
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033219F9 1_2_033219F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033295FD 1_2_033295FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0333F9E3 1_2_0333F9E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332A5E1 1_2_0332A5E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B1E1 1_2_0332B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033209EA 1_2_033209EA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033255ED 1_2_033255ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332C1ED 1_2_0332C1ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033429D7 1_2_033429D7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033215DB 1_2_033215DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321436 1_2_03321436
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DC18 1_2_0332DC18
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332181E 1_2_0332181E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332541C 1_2_0332541C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03325402 1_2_03325402
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320001 1_2_03320001
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332000E 1_2_0332000E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321C0D 1_2_03321C0D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03321C6E 1_2_03321C6E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332986D 1_2_0332986D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332205D 1_2_0332205D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03341447 1_2_03341447
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329844 1_2_03329844
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332044C 1_2_0332044C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033214BF 1_2_033214BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033204A4 1_2_033204A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033200AB 1_2_033200AB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320894 1_2_03320894
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03337095 1_2_03337095
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320C98 1_2_03320C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332D898 1_2_0332D898
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332188F 1_2_0332188F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033294E1 1_2_033294E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033224E8 1_2_033224E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033224C0 1_2_033224C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332E0C0 1_2_0332E0C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0D69 5_2_1D7A0D69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85FD27 5_2_1D85FD27
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A9DD0 5_2_1D7A9DD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D857D4C 5_2_1D857D4C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B2DB0 5_2_1D7B2DB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D839C98 5_2_1D839C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AAC20 5_2_1D7AAC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D827CE8 5_2_1D827CE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D790C12 5_2_1D790C12
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D86ACEB 5_2_1D86ACEB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BFCE0 5_2_1D7BFCE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81EC20 5_2_1D81EC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B8CDF 5_2_1D7B8CDF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84EC4C 5_2_1D84EC4C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85EC60 5_2_1D85EC60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D856C69 5_2_1D856C69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85EFBF 5_2_1D85EFBF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D851FC6 5_2_1D851FC6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ACF00 5_2_1D7ACF00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81FF40 5_2_1D81FF40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85FF63 5_2_1D85FF63
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D850EAD 5_2_1D850EAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C0E50 5_2_1D7C0E50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D859ED2 5_2_1D859ED2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792EE8 5_2_1D792EE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85E9A6 5_2_1D85E9A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E59C0 5_2_1D7E59C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A9870 5_2_1D7A9870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BB870 5_2_1D7BB870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D786868 5_2_1D786868
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8198B2 5_2_1D8198B2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8518DA 5_2_1D8518DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CE810 5_2_1D7CE810
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8578F3 5_2_1D8578F3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3800 5_2_1D7A3800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840835 5_2_1D840835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A28C0 5_2_1D7A28C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D815870 5_2_1D815870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85F872 5_2_1D85F872
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B6882 5_2_1D7B6882
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D814BC0 5_2_1D814BC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7DDB19 5_2_1D7DDB19
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0B10 5_2_1D7A0B10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85FB2E 5_2_1D85FB2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85FA89 5_2_1D85FA89
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85CA13 5_2_1D85CA13
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BFAA0 5_2_1D7BFAA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85EA5B 5_2_1D85EA5B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8575C6 5_2_1D8575C6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85F5C9 5_2_1D85F5C9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D86A526 5_2_1D86A526
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80D480 5_2_1D80D480
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0445 5_2_1D7A0445
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A2760 5_2_1D7A2760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AA760 5_2_1D7AA760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D856757 5_2_1D856757
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C4670 5_2_1D7C4670
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85A6C0 5_2_1D85A6C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8136EC 5_2_1D8136EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85F6F6 5_2_1D85F6F6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BC600 5_2_1D7BC600
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79C6E0 5_2_1D79C6E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83D62C 5_2_1D83D62C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84D646 5_2_1D84D646
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0680 5_2_1D7A0680
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E717A 5_2_1D7E717A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78F113 5_2_1D78F113
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D86010E 5_2_1D86010E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BB1E0 5_2_1D7BB1E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83D130 5_2_1D83D130
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A51C0 5_2_1D7A51C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8570F1 5_2_1D8570F1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AB0D0 5_2_1D7AB0D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7900A0 5_2_1D7900A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D508C 5_2_1D7D508C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84E076 5_2_1D84E076
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AE310 5_2_1D7AE310
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85F330 5_2_1D85F330
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791380 5_2_1D791380
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78D2EC 5_2_1D78D2EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85124C 5_2_1D85124C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_016806CD 5_2_016806CD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: String function: 1D7D5050 appears 36 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: String function: 1D81EF10 appears 105 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: String function: 1D7E7BE4 appears 97 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: String function: 1D78B910 appears 272 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: String function: 1D80E692 appears 86 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03330A7D NtWriteVirtualMemory, 1_2_03330A7D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03343960 NtProtectVirtualMemory, 1_2_03343960
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033449A1 NtResumeThread, 1_2_033449A1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2D10 NtQuerySystemInformation,LdrInitializeThunk, 5_2_1D7D2D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2B10 NtAllocateVirtualMemory,LdrInitializeThunk, 5_2_1D7D2B10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2B90 NtFreeVirtualMemory,LdrInitializeThunk, 5_2_1D7D2B90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2D50 NtWriteVirtualMemory, 5_2_1D7D2D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2DC0 NtAdjustPrivilegesToken, 5_2_1D7D2DC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2DA0 NtReadVirtualMemory, 5_2_1D7D2DA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2C50 NtUnmapViewOfSection, 5_2_1D7D2C50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D3C30 NtOpenProcessToken, 5_2_1D7D3C30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2C30 NtMapViewOfSection, 5_2_1D7D2C30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2C20 NtSetInformationFile, 5_2_1D7D2C20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2C10 NtOpenProcess, 5_2_1D7D2C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2CF0 NtDelayExecution, 5_2_1D7D2CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2CD0 NtEnumerateKey, 5_2_1D7D2CD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D3C90 NtOpenThread, 5_2_1D7D3C90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2F30 NtOpenDirectoryObject, 5_2_1D7D2F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2F00 NtCreateFile, 5_2_1D7D2F00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2FB0 NtSetValueKey, 5_2_1D7D2FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2E50 NtCreateSection, 5_2_1D7D2E50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2E00 NtQueueApcThread, 5_2_1D7D2E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2ED0 NtResumeThread, 5_2_1D7D2ED0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2EC0 NtQuerySection, 5_2_1D7D2EC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2EB0 NtProtectVirtualMemory, 5_2_1D7D2EB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2E80 NtCreateProcessEx, 5_2_1D7D2E80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D29F0 NtReadFile, 5_2_1D7D29F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D29D0 NtWaitForSingleObject, 5_2_1D7D29D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D38D0 NtGetContextThread, 5_2_1D7D38D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2B20 NtQueryInformationProcess, 5_2_1D7D2B20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2B00 NtQueryValueKey, 5_2_1D7D2B00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2BE0 NtQueryVirtualMemory, 5_2_1D7D2BE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2BC0 NtQueryInformationToken, 5_2_1D7D2BC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2B80 NtCreateKey, 5_2_1D7D2B80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2A10 NtWriteFile, 5_2_1D7D2A10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2AC0 NtEnumerateValueKey, 5_2_1D7D2AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2AA0 NtQueryInformationFile, 5_2_1D7D2AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D2A80 NtClose, 5_2_1D7D2A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D4570 NtSuspendThread, 5_2_1D7D4570
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D34E0 NtCreateMutant, 5_2_1D7D34E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D4260 NtSetContextThread, 5_2_1D7D4260
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39649421768.000000001D530000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44194181907.000000001D88D000.00000040.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39654608535.000000001D6E4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44196722142.000000001DA30000.00000040.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Section loaded: edgegdi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Section loaded: edgegdi.dll Jump to behavior
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: invalid certificate
Source: libgiognutls.dll.1.dr Static PE information: Number of sections : 11 > 10
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Virustotal: Detection: 29%
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe ReversingLabs: Detection: 19%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Jump to behavior
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0040344A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 1_2_0040344A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Local\Temp\nsp5029.tmp Jump to behavior
Source: classification engine Classification label: mal60.troj.evad.winEXE@3/4@1/1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00402104 CoCreateInstance, 1_2_00402104
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00404771 GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW, 1_2_00404771
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: mshtml.pdb source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39652897969.000000001D5B7000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44194181907.000000001D88D000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44191646427.000000001D760000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39647697379.000000001D40D000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39652897969.000000001D5B7000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44194181907.000000001D88D000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44191646427.000000001D760000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39647697379.000000001D40D000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: mshtml.pdbUGP source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000001.39482313722.0000000000649000.00000008.00000001.01000000.00000005.sdmp

Data Obfuscation

barindex
Source: Yara match File source: 00000001.00000002.39673477269.0000000003320000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000000.39479578905.0000000001660000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_10002DE0 push eax; ret 1_2_10002E0E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332733D push ds; retf 1_2_0332746E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03325773 pushad ; ret 1_2_03325877
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03331367 pushad ; iretd 1_2_03331373
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03325742 push ebp; iretd 1_2_03325771
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033273D0 push ds; retf 1_2_0332746E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332F3CB pushad ; iretd 1_2_0332F3F4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B629 push FFFFFFACh; retf 1_2_0332B6DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03330606 push esp; ret 1_2_03330607
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03327D33 push 8566BBEBh; ret 1_2_03327D38
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B571 push FFFFFFACh; retf 1_2_0332B6DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03325863 pushad ; ret 1_2_03325877
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03330C84 push ds; iretd 1_2_03330C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332B4F0 push FFFFFFACh; retf 1_2_0332B6DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332F4EA push esp; iretd 1_2_0332F4EB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7908CD push ecx; mov dword ptr [esp], ecx 5_2_1D7908D6
Source: libgiognutls.dll.1.dr Static PE information: section name: .xdata
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_10001B18 GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW, 1_2_10001B18
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen\Armoniac\libgiognutls.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Local\Temp\nsg51C2.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Obeyeo.Bib Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen\Armoniac Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen\Armoniac\libgiognutls.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen\Armoniac\Urokkeligheden.Ord114 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File opened: C:\Program Files\Qemu-ga\qemu-ga.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File opened: C:\Program Files\qga\qga.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File opened: C:\Program Files\Qemu-ga\qemu-ga.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe File opened: C:\Program Files\qga\qga.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\Vatersotiges\Knoglemarvsundersgelsen\Armoniac\libgiognutls.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320313 rdtsc 1_2_03320313
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe API coverage: 0.3 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00406555 FindFirstFileW,FindClose, 1_2_00406555
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_00405A03 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 1_2_00405A03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0040287E FindFirstFileW, 1_2_0040287E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe System information queried: ModuleInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe API call chain: ExitProcess graph end node
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Guest Shutdown Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Remote Desktop Virtualization Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmicshutdown
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Volume Shadow Copy Requestor
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V PowerShell Direct Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Time Synchronization Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmicvss
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39650788507.000000000194A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176068670.000000000190C000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44176520630.000000000194A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000003.39936791137.000000000194A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Data Exchange Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Heartbeat Service
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000001.00000002.39674469754.0000000010059000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Hyper-V Guest Service Interface
Source: SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe, 00000005.00000002.44177087962.00000000034C9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmicheartbeat
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_10001B18 GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW, 1_2_10001B18
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03320313 rdtsc 1_2_03320313
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DB33 mov eax, dword ptr fs:[00000030h] 1_2_0332DB33
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332DB35 mov eax, dword ptr fs:[00000030h] 1_2_0332DB35
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332CB5D mov eax, dword ptr fs:[00000030h] 1_2_0332CB5D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03329178 mov eax, dword ptr fs:[00000030h] 1_2_03329178
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332E5FD mov ebx, dword ptr fs:[00000030h] 1_2_0332E5FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332C1ED mov eax, dword ptr fs:[00000030h] 1_2_0332C1ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_033429D7 mov eax, dword ptr fs:[00000030h] 1_2_033429D7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332CC27 mov eax, dword ptr fs:[00000030h] 1_2_0332CC27
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0333202C mov eax, dword ptr fs:[00000030h] 1_2_0333202C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0332CC2D mov eax, dword ptr fs:[00000030h] 1_2_0332CC2D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03340817 mov eax, dword ptr fs:[00000030h] 1_2_03340817
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBD71 mov eax, dword ptr fs:[00000030h] 5_2_1D7CBD71
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBD71 mov eax, dword ptr fs:[00000030h] 5_2_1D7CBD71
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A5D60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A5D60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864DA7 mov eax, dword ptr fs:[00000030h] 5_2_1D864DA7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791D50 mov eax, dword ptr fs:[00000030h] 5_2_1D791D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791D50 mov eax, dword ptr fs:[00000030h] 5_2_1D791D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADD4D mov eax, dword ptr fs:[00000030h] 5_2_1D7ADD4D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADD4D mov eax, dword ptr fs:[00000030h] 5_2_1D7ADD4D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADD4D mov eax, dword ptr fs:[00000030h] 5_2_1D7ADD4D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D789D46 mov eax, dword ptr fs:[00000030h] 5_2_1D789D46
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D789D46 mov eax, dword ptr fs:[00000030h] 5_2_1D789D46
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D789D46 mov ecx, dword ptr fs:[00000030h] 5_2_1D789D46
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84ADD6 mov eax, dword ptr fs:[00000030h] 5_2_1D84ADD6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84ADD6 mov eax, dword ptr fs:[00000030h] 5_2_1D84ADD6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78FD20 mov eax, dword ptr fs:[00000030h] 5_2_1D78FD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov ecx, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAD20 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BCD10 mov eax, dword ptr fs:[00000030h] 5_2_1D7BCD10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BCD10 mov ecx, dword ptr fs:[00000030h] 5_2_1D7BCD10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85CDEB mov eax, dword ptr fs:[00000030h] 5_2_1D85CDEB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85CDEB mov eax, dword ptr fs:[00000030h] 5_2_1D85CDEB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D83FDF4 mov eax, dword ptr fs:[00000030h] 5_2_1D83FDF4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79AD00 mov eax, dword ptr fs:[00000030h] 5_2_1D79AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B0D01 mov eax, dword ptr fs:[00000030h] 5_2_1D7B0D01
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81CD00 mov eax, dword ptr fs:[00000030h] 5_2_1D81CD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81CD00 mov eax, dword ptr fs:[00000030h] 5_2_1D81CD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78EDFA mov eax, dword ptr fs:[00000030h] 5_2_1D78EDFA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D828D0A mov eax, dword ptr fs:[00000030h] 5_2_1D828D0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84BD08 mov eax, dword ptr fs:[00000030h] 5_2_1D84BD08
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84BD08 mov eax, dword ptr fs:[00000030h] 5_2_1D84BD08
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79BDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D79BDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BFDE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7BFDE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840D24 mov eax, dword ptr fs:[00000030h] 5_2_1D840D24
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840D24 mov eax, dword ptr fs:[00000030h] 5_2_1D840D24
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840D24 mov eax, dword ptr fs:[00000030h] 5_2_1D840D24
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840D24 mov eax, dword ptr fs:[00000030h] 5_2_1D840D24
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D788DCD mov eax, dword ptr fs:[00000030h] 5_2_1D788DCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2DBC mov eax, dword ptr fs:[00000030h] 5_2_1D7C2DBC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2DBC mov ecx, dword ptr fs:[00000030h] 5_2_1D7C2DBC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80CD40 mov eax, dword ptr fs:[00000030h] 5_2_1D80CD40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80CD40 mov eax, dword ptr fs:[00000030h] 5_2_1D80CD40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D855D43 mov eax, dword ptr fs:[00000030h] 5_2_1D855D43
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D855D43 mov eax, dword ptr fs:[00000030h] 5_2_1D855D43
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78DDB0 mov eax, dword ptr fs:[00000030h] 5_2_1D78DDB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864D4B mov eax, dword ptr fs:[00000030h] 5_2_1D864D4B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D797DB6 mov eax, dword ptr fs:[00000030h] 5_2_1D797DB6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D786DA6 mov eax, dword ptr fs:[00000030h] 5_2_1D786DA6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811D5E mov eax, dword ptr fs:[00000030h] 5_2_1D811D5E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D815D60 mov eax, dword ptr fs:[00000030h] 5_2_1D815D60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D865D65 mov eax, dword ptr fs:[00000030h] 5_2_1D865D65
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796D91 mov eax, dword ptr fs:[00000030h] 5_2_1D796D91
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CD8A mov eax, dword ptr fs:[00000030h] 5_2_1D78CD8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CD8A mov eax, dword ptr fs:[00000030h] 5_2_1D78CD8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D836D79 mov esi, dword ptr fs:[00000030h] 5_2_1D836D79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D790C79 mov eax, dword ptr fs:[00000030h] 5_2_1D790C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D790C79 mov eax, dword ptr fs:[00000030h] 5_2_1D790C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D790C79 mov eax, dword ptr fs:[00000030h] 5_2_1D790C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D798C79 mov eax, dword ptr fs:[00000030h] 5_2_1D798C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D798C79 mov eax, dword ptr fs:[00000030h] 5_2_1D798C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D798C79 mov eax, dword ptr fs:[00000030h] 5_2_1D798C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D798C79 mov eax, dword ptr fs:[00000030h] 5_2_1D798C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D798C79 mov eax, dword ptr fs:[00000030h] 5_2_1D798C79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D813C80 mov ecx, dword ptr fs:[00000030h] 5_2_1D813C80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CC68 mov eax, dword ptr fs:[00000030h] 5_2_1D78CC68
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84FC95 mov eax, dword ptr fs:[00000030h] 5_2_1D84FC95
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBC6E mov eax, dword ptr fs:[00000030h] 5_2_1D7CBC6E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBC6E mov eax, dword ptr fs:[00000030h] 5_2_1D7CBC6E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C60 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D839C98 mov ecx, dword ptr fs:[00000030h] 5_2_1D839C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D839C98 mov eax, dword ptr fs:[00000030h] 5_2_1D839C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D839C98 mov eax, dword ptr fs:[00000030h] 5_2_1D839C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D839C98 mov eax, dword ptr fs:[00000030h] 5_2_1D839C98
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78DC40 mov eax, dword ptr fs:[00000030h] 5_2_1D78DC40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C40 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C4C3D mov eax, dword ptr fs:[00000030h] 5_2_1D7C4C3D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D788C3D mov eax, dword ptr fs:[00000030h] 5_2_1D788C3D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D815CD0 mov eax, dword ptr fs:[00000030h] 5_2_1D815CD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D822CD0 mov eax, dword ptr fs:[00000030h] 5_2_1D822CD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D822CD0 mov eax, dword ptr fs:[00000030h] 5_2_1D822CD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D822CD0 mov eax, dword ptr fs:[00000030h] 5_2_1D822CD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864CD2 mov eax, dword ptr fs:[00000030h] 5_2_1D864CD2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D823CD4 mov eax, dword ptr fs:[00000030h] 5_2_1D823CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D823CD4 mov eax, dword ptr fs:[00000030h] 5_2_1D823CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D823CD4 mov ecx, dword ptr fs:[00000030h] 5_2_1D823CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D823CD4 mov eax, dword ptr fs:[00000030h] 5_2_1D823CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D823CD4 mov eax, dword ptr fs:[00000030h] 5_2_1D823CD4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A3C20 mov eax, dword ptr fs:[00000030h] 5_2_1D7A3C20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AAC20 mov eax, dword ptr fs:[00000030h] 5_2_1D7AAC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AAC20 mov eax, dword ptr fs:[00000030h] 5_2_1D7AAC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7AAC20 mov eax, dword ptr fs:[00000030h] 5_2_1D7AAC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D827CE8 mov eax, dword ptr fs:[00000030h] 5_2_1D827CE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2C10 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2C10 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2C10 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2C10 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D810CEE mov eax, dword ptr fs:[00000030h] 5_2_1D810CEE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80CCF0 mov ecx, dword ptr fs:[00000030h] 5_2_1D80CCF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BECF3 mov eax, dword ptr fs:[00000030h] 5_2_1D7BECF3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BECF3 mov eax, dword ptr fs:[00000030h] 5_2_1D7BECF3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787CF1 mov eax, dword ptr fs:[00000030h] 5_2_1D787CF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793CF0 mov eax, dword ptr fs:[00000030h] 5_2_1D793CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793CF0 mov eax, dword ptr fs:[00000030h] 5_2_1D793CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B8CDF mov eax, dword ptr fs:[00000030h] 5_2_1D7B8CDF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B8CDF mov eax, dword ptr fs:[00000030h] 5_2_1D7B8CDF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADCD1 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADCD1 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADCD1 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCCD1 mov ecx, dword ptr fs:[00000030h] 5_2_1D7CCCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCCD1 mov eax, dword ptr fs:[00000030h] 5_2_1D7CCCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCCD1 mov eax, dword ptr fs:[00000030h] 5_2_1D7CCCD1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79FCC9 mov eax, dword ptr fs:[00000030h] 5_2_1D79FCC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C9CCF mov eax, dword ptr fs:[00000030h] 5_2_1D7C9CCF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D786CC0 mov eax, dword ptr fs:[00000030h] 5_2_1D786CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D786CC0 mov eax, dword ptr fs:[00000030h] 5_2_1D786CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D786CC0 mov eax, dword ptr fs:[00000030h] 5_2_1D786CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D827C38 mov eax, dword ptr fs:[00000030h] 5_2_1D827C38
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C6CC0 mov eax, dword ptr fs:[00000030h] 5_2_1D7C6CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D855C38 mov eax, dword ptr fs:[00000030h] 5_2_1D855C38
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D855C38 mov ecx, dword ptr fs:[00000030h] 5_2_1D855C38
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D813C57 mov eax, dword ptr fs:[00000030h] 5_2_1D813C57
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864C59 mov eax, dword ptr fs:[00000030h] 5_2_1D864C59
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D797C95 mov eax, dword ptr fs:[00000030h] 5_2_1D797C95
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D797C95 mov eax, dword ptr fs:[00000030h] 5_2_1D797C95
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787C85 mov eax, dword ptr fs:[00000030h] 5_2_1D787C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787C85 mov eax, dword ptr fs:[00000030h] 5_2_1D787C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787C85 mov eax, dword ptr fs:[00000030h] 5_2_1D787C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787C85 mov eax, dword ptr fs:[00000030h] 5_2_1D787C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787C85 mov eax, dword ptr fs:[00000030h] 5_2_1D787C85
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78EF79 mov eax, dword ptr fs:[00000030h] 5_2_1D78EF79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78EF79 mov eax, dword ptr fs:[00000030h] 5_2_1D78EF79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78EF79 mov eax, dword ptr fs:[00000030h] 5_2_1D78EF79
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78BF70 mov eax, dword ptr fs:[00000030h] 5_2_1D78BF70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791F70 mov eax, dword ptr fs:[00000030h] 5_2_1D791F70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAF72 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAF72
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F8B mov eax, dword ptr fs:[00000030h] 5_2_1D818F8B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F8B mov eax, dword ptr fs:[00000030h] 5_2_1D818F8B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F8B mov eax, dword ptr fs:[00000030h] 5_2_1D818F8B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E6F70 mov eax, dword ptr fs:[00000030h] 5_2_1D7E6F70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78FF30 mov edi, dword ptr fs:[00000030h] 5_2_1D78FF30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D811FC9 mov eax, dword ptr fs:[00000030h] 5_2_1D811FC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADF36 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADF36
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADF36 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADF36
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADF36 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADF36
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ADF36 mov eax, dword ptr fs:[00000030h] 5_2_1D7ADF36
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84EFD3 mov eax, dword ptr fs:[00000030h] 5_2_1D84EFD3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov eax, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov eax, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov eax, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov ecx, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov eax, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FFDC mov eax, dword ptr fs:[00000030h] 5_2_1D80FFDC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D0F16 mov eax, dword ptr fs:[00000030h] 5_2_1D7D0F16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D0F16 mov eax, dword ptr fs:[00000030h] 5_2_1D7D0F16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D0F16 mov eax, dword ptr fs:[00000030h] 5_2_1D7D0F16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D0F16 mov eax, dword ptr fs:[00000030h] 5_2_1D7D0F16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBF0C mov eax, dword ptr fs:[00000030h] 5_2_1D7CBF0C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBF0C mov eax, dword ptr fs:[00000030h] 5_2_1D7CBF0C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBF0C mov eax, dword ptr fs:[00000030h] 5_2_1D7CBF0C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864FFF mov eax, dword ptr fs:[00000030h] 5_2_1D864FFF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ACF00 mov eax, dword ptr fs:[00000030h] 5_2_1D7ACF00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7ACF00 mov eax, dword ptr fs:[00000030h] 5_2_1D7ACF00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B8FFB mov eax, dword ptr fs:[00000030h] 5_2_1D7B8FFB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FF03 mov eax, dword ptr fs:[00000030h] 5_2_1D80FF03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FF03 mov eax, dword ptr fs:[00000030h] 5_2_1D80FF03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FF03 mov eax, dword ptr fs:[00000030h] 5_2_1D80FF03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A6FE0 mov eax, dword ptr fs:[00000030h] 5_2_1D7A6FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864F1D mov eax, dword ptr fs:[00000030h] 5_2_1D864F1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D789FD0 mov eax, dword ptr fs:[00000030h] 5_2_1D789FD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78BFC0 mov eax, dword ptr fs:[00000030h] 5_2_1D78BFC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F3C mov eax, dword ptr fs:[00000030h] 5_2_1D818F3C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F3C mov eax, dword ptr fs:[00000030h] 5_2_1D818F3C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F3C mov ecx, dword ptr fs:[00000030h] 5_2_1D818F3C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D818F3C mov ecx, dword ptr fs:[00000030h] 5_2_1D818F3C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C8FBC mov eax, dword ptr fs:[00000030h] 5_2_1D7C8FBC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84BF4D mov eax, dword ptr fs:[00000030h] 5_2_1D84BF4D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BCFB0 mov eax, dword ptr fs:[00000030h] 5_2_1D7BCFB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BCFB0 mov eax, dword ptr fs:[00000030h] 5_2_1D7BCFB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D794FB6 mov eax, dword ptr fs:[00000030h] 5_2_1D794FB6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791FAA mov eax, dword ptr fs:[00000030h] 5_2_1D791FAA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84AF50 mov ecx, dword ptr fs:[00000030h] 5_2_1D84AF50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84EF66 mov eax, dword ptr fs:[00000030h] 5_2_1D84EF66
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BBF93 mov eax, dword ptr fs:[00000030h] 5_2_1D7BBF93
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A0F90 mov eax, dword ptr fs:[00000030h] 5_2_1D7A0F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864F7C mov eax, dword ptr fs:[00000030h] 5_2_1D864F7C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D791E70 mov eax, dword ptr fs:[00000030h] 5_2_1D791E70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCE70 mov eax, dword ptr fs:[00000030h] 5_2_1D7CCE70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C7E71 mov eax, dword ptr fs:[00000030h] 5_2_1D7C7E71
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78BE60 mov eax, dword ptr fs:[00000030h] 5_2_1D78BE60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78BE60 mov eax, dword ptr fs:[00000030h] 5_2_1D78BE60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D850EAD mov eax, dword ptr fs:[00000030h] 5_2_1D850EAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D850EAD mov eax, dword ptr fs:[00000030h] 5_2_1D850EAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BEE48 mov eax, dword ptr fs:[00000030h] 5_2_1D7BEE48
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78FE40 mov eax, dword ptr fs:[00000030h] 5_2_1D78FE40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78AE40 mov eax, dword ptr fs:[00000030h] 5_2_1D78AE40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78AE40 mov eax, dword ptr fs:[00000030h] 5_2_1D78AE40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78AE40 mov eax, dword ptr fs:[00000030h] 5_2_1D78AE40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78DE45 mov eax, dword ptr fs:[00000030h] 5_2_1D78DE45
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78DE45 mov ecx, dword ptr fs:[00000030h] 5_2_1D78DE45
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D817EC3 mov eax, dword ptr fs:[00000030h] 5_2_1D817EC3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D817EC3 mov ecx, dword ptr fs:[00000030h] 5_2_1D817EC3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCE3F mov eax, dword ptr fs:[00000030h] 5_2_1D7CCE3F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864EC1 mov eax, dword ptr fs:[00000030h] 5_2_1D864EC1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792E32 mov eax, dword ptr fs:[00000030h] 5_2_1D792E32
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81CED0 mov ecx, dword ptr fs:[00000030h] 5_2_1D81CED0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D859ED2 mov eax, dword ptr fs:[00000030h] 5_2_1D859ED2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78BE18 mov ecx, dword ptr fs:[00000030h] 5_2_1D78BE18
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84EEE7 mov eax, dword ptr fs:[00000030h] 5_2_1D84EEE7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C8E15 mov eax, dword ptr fs:[00000030h] 5_2_1D7C8E15
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793E14 mov eax, dword ptr fs:[00000030h] 5_2_1D793E14
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793E14 mov eax, dword ptr fs:[00000030h] 5_2_1D793E14
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793E14 mov eax, dword ptr fs:[00000030h] 5_2_1D793E14
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793E01 mov eax, dword ptr fs:[00000030h] 5_2_1D793E01
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796E00 mov eax, dword ptr fs:[00000030h] 5_2_1D796E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796E00 mov eax, dword ptr fs:[00000030h] 5_2_1D796E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796E00 mov eax, dword ptr fs:[00000030h] 5_2_1D796E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796E00 mov eax, dword ptr fs:[00000030h] 5_2_1D796E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D833EFC mov eax, dword ptr fs:[00000030h] 5_2_1D833EFC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864E03 mov eax, dword ptr fs:[00000030h] 5_2_1D864E03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78CEF0 mov eax, dword ptr fs:[00000030h] 5_2_1D78CEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C1EED mov eax, dword ptr fs:[00000030h] 5_2_1D7C1EED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C1EED mov eax, dword ptr fs:[00000030h] 5_2_1D7C1EED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C1EED mov eax, dword ptr fs:[00000030h] 5_2_1D7C1EED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792EE8 mov eax, dword ptr fs:[00000030h] 5_2_1D792EE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792EE8 mov eax, dword ptr fs:[00000030h] 5_2_1D792EE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792EE8 mov eax, dword ptr fs:[00000030h] 5_2_1D792EE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D792EE8 mov eax, dword ptr fs:[00000030h] 5_2_1D792EE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D793EE2 mov eax, dword ptr fs:[00000030h] 5_2_1D793EE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FE1F mov eax, dword ptr fs:[00000030h] 5_2_1D80FE1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FE1F mov eax, dword ptr fs:[00000030h] 5_2_1D80FE1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FE1F mov eax, dword ptr fs:[00000030h] 5_2_1D80FE1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80FE1F mov eax, dword ptr fs:[00000030h] 5_2_1D80FE1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D858E26 mov eax, dword ptr fs:[00000030h] 5_2_1D858E26
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D858E26 mov eax, dword ptr fs:[00000030h] 5_2_1D858E26
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D858E26 mov eax, dword ptr fs:[00000030h] 5_2_1D858E26
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D858E26 mov eax, dword ptr fs:[00000030h] 5_2_1D858E26
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7D1ED8 mov eax, dword ptr fs:[00000030h] 5_2_1D7D1ED8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CBED0 mov eax, dword ptr fs:[00000030h] 5_2_1D7CBED0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D826E30 mov eax, dword ptr fs:[00000030h] 5_2_1D826E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D826E30 mov eax, dword ptr fs:[00000030h] 5_2_1D826E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov eax, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov ecx, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov eax, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov eax, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov eax, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825E30 mov eax, dword ptr fs:[00000030h] 5_2_1D825E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2EB8 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2EB8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2EB8 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2EB8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov eax, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov eax, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov eax, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov ecx, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A1EB2 mov eax, dword ptr fs:[00000030h] 5_2_1D7A1EB2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80DE50 mov eax, dword ptr fs:[00000030h] 5_2_1D80DE50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80DE50 mov eax, dword ptr fs:[00000030h] 5_2_1D80DE50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80DE50 mov ecx, dword ptr fs:[00000030h] 5_2_1D80DE50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80DE50 mov eax, dword ptr fs:[00000030h] 5_2_1D80DE50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80DE50 mov eax, dword ptr fs:[00000030h] 5_2_1D80DE50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CCEA0 mov eax, dword ptr fs:[00000030h] 5_2_1D7CCEA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D864E62 mov eax, dword ptr fs:[00000030h] 5_2_1D864E62
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D840E6D mov eax, dword ptr fs:[00000030h] 5_2_1D840E6D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAE89 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAE89
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BAE89 mov eax, dword ptr fs:[00000030h] 5_2_1D7BAE89
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BBE80 mov eax, dword ptr fs:[00000030h] 5_2_1D7BBE80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84EE78 mov eax, dword ptr fs:[00000030h] 5_2_1D84EE78
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D796970 mov eax, dword ptr fs:[00000030h] 5_2_1D796970
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A096B mov eax, dword ptr fs:[00000030h] 5_2_1D7A096B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A096B mov eax, dword ptr fs:[00000030h] 5_2_1D7A096B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8189A0 mov eax, dword ptr fs:[00000030h] 5_2_1D8189A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CC958 mov eax, dword ptr fs:[00000030h] 5_2_1D7CC958
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov eax, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov ecx, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov eax, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov eax, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov eax, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B950 mov eax, dword ptr fs:[00000030h] 5_2_1D79B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81F9AA mov eax, dword ptr fs:[00000030h] 5_2_1D81F9AA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81F9AA mov eax, dword ptr fs:[00000030h] 5_2_1D81F9AA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B4955 mov eax, dword ptr fs:[00000030h] 5_2_1D7B4955
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B4955 mov eax, dword ptr fs:[00000030h] 5_2_1D7B4955
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8269B0 mov eax, dword ptr fs:[00000030h] 5_2_1D8269B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8269B0 mov eax, dword ptr fs:[00000030h] 5_2_1D8269B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8269B0 mov ecx, dword ptr fs:[00000030h] 5_2_1D8269B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BE94E mov eax, dword ptr fs:[00000030h] 5_2_1D7BE94E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CC944 mov eax, dword ptr fs:[00000030h] 5_2_1D7CC944
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BD940 mov eax, dword ptr fs:[00000030h] 5_2_1D7BD940
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BD940 mov eax, dword ptr fs:[00000030h] 5_2_1D7BD940
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84D9C6 mov eax, dword ptr fs:[00000030h] 5_2_1D84D9C6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7B9938 mov ecx, dword ptr fs:[00000030h] 5_2_1D7B9938
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E693A mov eax, dword ptr fs:[00000030h] 5_2_1D7E693A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E693A mov eax, dword ptr fs:[00000030h] 5_2_1D7E693A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E693A mov eax, dword ptr fs:[00000030h] 5_2_1D7E693A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81D9C7 mov eax, dword ptr fs:[00000030h] 5_2_1D81D9C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78B931 mov eax, dword ptr fs:[00000030h] 5_2_1D78B931
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78B931 mov eax, dword ptr fs:[00000030h] 5_2_1D78B931
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8629CF mov eax, dword ptr fs:[00000030h] 5_2_1D8629CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8629CF mov eax, dword ptr fs:[00000030h] 5_2_1D8629CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8399D6 mov ecx, dword ptr fs:[00000030h] 5_2_1D8399D6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C5921 mov eax, dword ptr fs:[00000030h] 5_2_1D7C5921
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C5921 mov ecx, dword ptr fs:[00000030h] 5_2_1D7C5921
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C5921 mov eax, dword ptr fs:[00000030h] 5_2_1D7C5921
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C5921 mov eax, dword ptr fs:[00000030h] 5_2_1D7C5921
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2919 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2919
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C2919 mov eax, dword ptr fs:[00000030h] 5_2_1D7C2919
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7E6912 mov eax, dword ptr fs:[00000030h] 5_2_1D7E6912
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D787917 mov eax, dword ptr fs:[00000030h] 5_2_1D787917
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BB9FA mov eax, dword ptr fs:[00000030h] 5_2_1D7BB9FA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7899F0 mov ecx, dword ptr fs:[00000030h] 5_2_1D7899F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7909F0 mov eax, dword ptr fs:[00000030h] 5_2_1D7909F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C49F0 mov eax, dword ptr fs:[00000030h] 5_2_1D7C49F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C49F0 mov eax, dword ptr fs:[00000030h] 5_2_1D7C49F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80C920 mov ecx, dword ptr fs:[00000030h] 5_2_1D80C920
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80C920 mov eax, dword ptr fs:[00000030h] 5_2_1D80C920
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80C920 mov eax, dword ptr fs:[00000030h] 5_2_1D80C920
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D80C920 mov eax, dword ptr fs:[00000030h] 5_2_1D80C920
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85892E mov eax, dword ptr fs:[00000030h] 5_2_1D85892E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85892E mov eax, dword ptr fs:[00000030h] 5_2_1D85892E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D86492D mov eax, dword ptr fs:[00000030h] 5_2_1D86492D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825930 mov eax, dword ptr fs:[00000030h] 5_2_1D825930
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825930 mov eax, dword ptr fs:[00000030h] 5_2_1D825930
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825930 mov eax, dword ptr fs:[00000030h] 5_2_1D825930
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D825930 mov ecx, dword ptr fs:[00000030h] 5_2_1D825930
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BD9CE mov eax, dword ptr fs:[00000030h] 5_2_1D7BD9CE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B9C0 mov eax, dword ptr fs:[00000030h] 5_2_1D79B9C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79B9C0 mov eax, dword ptr fs:[00000030h] 5_2_1D79B9C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7989C0 mov eax, dword ptr fs:[00000030h] 5_2_1D7989C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7989C0 mov eax, dword ptr fs:[00000030h] 5_2_1D7989C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D85D946 mov eax, dword ptr fs:[00000030h] 5_2_1D85D946
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D84D947 mov eax, dword ptr fs:[00000030h] 5_2_1D84D947
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78B9B0 mov eax, dword ptr fs:[00000030h] 5_2_1D78B9B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7C89B0 mov edx, dword ptr fs:[00000030h] 5_2_1D7C89B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79E9A0 mov eax, dword ptr fs:[00000030h] 5_2_1D79E9A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81395B mov eax, dword ptr fs:[00000030h] 5_2_1D81395B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81395B mov eax, dword ptr fs:[00000030h] 5_2_1D81395B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81395B mov eax, dword ptr fs:[00000030h] 5_2_1D81395B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CC98F mov eax, dword ptr fs:[00000030h] 5_2_1D7CC98F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CC98F mov eax, dword ptr fs:[00000030h] 5_2_1D7CC98F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7CC98F mov eax, dword ptr fs:[00000030h] 5_2_1D7CC98F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79F870 mov eax, dword ptr fs:[00000030h] 5_2_1D79F870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D79F870 mov eax, dword ptr fs:[00000030h] 5_2_1D79F870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A9870 mov eax, dword ptr fs:[00000030h] 5_2_1D7A9870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7A9870 mov eax, dword ptr fs:[00000030h] 5_2_1D7A9870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D831889 mov eax, dword ptr fs:[00000030h] 5_2_1D831889
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D831889 mov eax, dword ptr fs:[00000030h] 5_2_1D831889
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D831889 mov eax, dword ptr fs:[00000030h] 5_2_1D831889
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81488F mov eax, dword ptr fs:[00000030h] 5_2_1D81488F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81B890 mov eax, dword ptr fs:[00000030h] 5_2_1D81B890
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81B890 mov eax, dword ptr fs:[00000030h] 5_2_1D81B890
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D81B890 mov ecx, dword ptr fs:[00000030h] 5_2_1D81B890
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D848890 mov eax, dword ptr fs:[00000030h] 5_2_1D848890
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D848890 mov eax, dword ptr fs:[00000030h] 5_2_1D848890
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8198B2 mov eax, dword ptr fs:[00000030h] 5_2_1D8198B2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D7BB839 mov eax, dword ptr fs:[00000030h] 5_2_1D7BB839
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8518DA mov eax, dword ptr fs:[00000030h] 5_2_1D8518DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8518DA mov eax, dword ptr fs:[00000030h] 5_2_1D8518DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8518DA mov eax, dword ptr fs:[00000030h] 5_2_1D8518DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D8518DA mov eax, dword ptr fs:[00000030h] 5_2_1D8518DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 5_2_1D78D818 mov eax, dword ptr fs:[00000030h] 5_2_1D78D818
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_03340888 LdrLoadDll, 1_2_03340888
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.11060.2891.exe Code function: 1_2_0040344A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 1_2_0040344A
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs