Windows Analysis Report
SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe

Overview

General Information

Sample Name: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe
Analysis ID: 800798
MD5: 97011b19f2683a918f1f07f7f4ec1998
SHA1: 4b486d0b67994fabe961787f5facdf9a0e3f6672
SHA256: c1469167b9700aeca987573c023ec7f160dadf8309a7a4feb2cd1969ad66673e
Tags: exe
Infos:

Detection

Score: 32
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Multi AV Scanner detection for submitted file
Multi AV Scanner detection for dropped file
Machine Learning detection for sample
Machine Learning detection for dropped file
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
Contains functionality to shutdown / reboot the system
Detected potential crypto function
Stores files to the Windows start menu directory
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
Creates a DirectInput object (often for capturing keystrokes)
Drops PE files
Creates a start menu entry (Start Menu\Programs\Startup)
Creates a process in suspended mode (likely to inject code)
Contains functionality for read data from the clipboard

Classification

AV Detection

barindex
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe ReversingLabs: Detection: 17%
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Virustotal: Detection: 19% Perma Link
Source: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe ReversingLabs: Detection: 23%
Source: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe ReversingLabs: Detection: 17%
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe ReversingLabs: Detection: 14%
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Joe Sandbox ML: detected
Source: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe Joe Sandbox ML: detected
Source: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe Joe Sandbox ML: detected
Source: 1.2.ModSource UI Addon Pack.exe.2c18226.6.unpack Avira: Label: TR/Patched.Ren.Gen
Source: 1.2.ModSource UI Addon Pack.exe.2bed809.4.unpack Avira: Label: TR/Patched.Ren.Gen
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\reticle_readme.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\readme_BattleBackground.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme_Anachs_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\ModSource UI Addon Pack Uninstall.log Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Ui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_chat_window_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_mfd_status_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_all_targets.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_targets_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_secondary_targets_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_pet.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_sml_group_window.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_radar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_location_display.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_exp_mon_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_collections.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_buttonbar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space_buttonbar.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_toolbar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space_toolbar.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_styles.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_palette_ground.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_palette_space.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_net_status.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Texture Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\heavyweapons_reticule.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\reticle_readme.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_activate.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_attack.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_big.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_crafting.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_deactivate.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_death_blow.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_default.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drag_bad.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drag_scroll.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drop.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_eat.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_equip.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_hourglass.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_intended_attack.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_mission_details.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_move.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_open.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_pickup.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_hor.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_se.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_sw.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_vert.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_stop_talk.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_talk.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_throw.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_trade_accepted.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_trade_start.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_unequip.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_use.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_target_inactive.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_background_arrow.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\readme_BattleBackground.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Sample Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_incoming_mail.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_fusioncutter_end.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_toggle_mouse_mode.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_use_toolbar.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_popup.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_arrow_back.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_arrow_forward.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_confirm.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_dialog_warning.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_increment_big.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_menu_close.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_rollover.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_info.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_rotate.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_open_metal_can_cntner.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_close_metal_can_cntner.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_negative.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Changelog_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme_Anachs_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Readme.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Web.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Update.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Uninstall.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.exe Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\GoogleUpdater Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\ModSource UI Addon Pack Uninstall.log Jump to behavior
Source: Binary string: q.pdB source: ModSource UI Addon Pack.exe.0.dr, ModSource UI Addon Pack.zip.0.dr
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405368 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_00405368
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405D3A FindFirstFileA,FindClose, 0_2_00405D3A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00402630 FindFirstFileA, 0_2_00402630
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00405368 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 1_2_00405368
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00405D3A FindFirstFileA,FindClose, 1_2_00405D3A
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00402630 FindFirstFileA, 1_2_00402630
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: Joe Sandbox View IP Address: 239.255.255.250 239.255.255.250
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 07 Feb 2023 18:59:10 GMTServer: ApacheX-BP-NSA-REQID: (null) n.12UID=1146X-Content-Type-Options: nosniffUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 29 May 2018 23:27:39 GMTETag: "1b63-56d60947c10c0"Accept-Ranges: bytesContent-Length: 7011Vary: Accept-EncodingContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 61 75 74 2d 68 6f 72 22 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 6d 69 72 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 65 76 69 73 69 74 2d 61 66 74 65 72 22 20 63 6f 6e 74 65 6e 74 3d 22 33 20 64 61 79 73 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 4e 4f 49 4e 44 45 58 2c 20 46 4f 4c 4c 4f 57 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 68 65 69 67 68 74 3d 64 65 76 69 63 65 2d 68 65 69 67 68 74 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 22 20 73 69 7a 65 73 3d 22 31 38 30 78 31 38 30 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 2e 70 6e 67 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 66 61 76 69 63 6f 6e 2d 33 32 78 33 32 2e 70 6e 67 22 20 73 69 7a 65 73 3d 22 33 32 78 33 32 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 6
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 07 Feb 2023 18:59:10 GMTServer: ApacheX-BP-NSA-REQID: (null) n.12UID=1562X-Content-Type-Options: nosniffUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 29 May 2018 23:27:39 GMTETag: "1b63-56d60947c10c0"Accept-Ranges: bytesContent-Length: 7011Vary: Accept-EncodingContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 61 75 74 2d 68 6f 72 22 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 6d 69 72 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 65 76 69 73 69 74 2d 61 66 74 65 72 22 20 63 6f 6e 74 65 6e 74 3d 22 33 20 64 61 79 73 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 4e 4f 49 4e 44 45 58 2c 20 46 4f 4c 4c 4f 57 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 68 65 69 67 68 74 3d 64 65 76 69 63 65 2d 68 65 69 67 68 74 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 22 20 73 69 7a 65 73 3d 22 31 38 30 78 31 38 30 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 2e 70 6e 67 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 66 61 76 69 63 6f 6e 2d 33 32 78 33 32 2e 70 6e 67 22 20 73 69 7a 65 73 3d 22 33 32 78 33 32 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 6
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 07 Feb 2023 18:59:15 GMTServer: ApacheX-BP-NSA-REQID: (null) n.12UID=1888X-Content-Type-Options: nosniffUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 29 May 2018 23:27:39 GMTETag: "1b63-56d60947c10c0"Accept-Ranges: bytesContent-Length: 7011Vary: Accept-EncodingContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 61 75 74 2d 68 6f 72 22 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 6d 69 72 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 65 76 69 73 69 74 2d 61 66 74 65 72 22 20 63 6f 6e 74 65 6e 74 3d 22 33 20 64 61 79 73 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 4e 4f 49 4e 44 45 58 2c 20 46 4f 4c 4c 4f 57 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 68 65 69 67 68 74 3d 64 65 76 69 63 65 2d 68 65 69 67 68 74 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 22 20 73 69 7a 65 73 3d 22 31 38 30 78 31 38 30 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 2e 70 6e 67 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 66 61 76 69 63 6f 6e 2d 33 32 78 33 32 2e 70 6e 67 22 20 73 69 7a 65 73 3d 22 33 32 78 33 32 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 6
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 07 Feb 2023 18:59:15 GMTServer: ApacheX-BP-NSA-REQID: (null) n.12UID=827X-Content-Type-Options: nosniffUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 29 May 2018 23:27:39 GMTETag: "1b63-56d60947c10c0"Accept-Ranges: bytesContent-Length: 7011Vary: Accept-EncodingContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 61 75 74 2d 68 6f 72 22 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 6d 69 72 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 65 76 69 73 69 74 2d 61 66 74 65 72 22 20 63 6f 6e 74 65 6e 74 3d 22 33 20 64 61 79 73 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 20 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 4e 4f 49 4e 44 45 58 2c 20 46 4f 4c 4c 4f 57 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 20 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 68 65 69 67 68 74 3d 64 65 76 69 63 65 2d 68 65 69 67 68 74 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 22 20 73 69 7a 65 73 3d 22 31 38 30 78 31 38 30 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 61 70 70 6c 65 2d 74 6f 75 63 68 2d 69 63 6f 6e 2e 70 6e 67 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 66 61 76 69 63 6f 6e 2d 33 32 78 33 32 2e 70 6e 67 22 20 73 69 7a 65 73 3d 22 33 32 78 33 32 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 70 6e 67 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 70 6c 61 63 65 64 2e 6e 65 74 2f 66
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 18:59:16 GMTServer: ApacheX-Frame-Options: SAMEORIGINLast-Modified: Sun, 16 Aug 2009 06:01:33 GMTETag: "57074349-111d8d-4713c046be940"Accept-Ranges: bytesContent-Length: 1121677Connection: closeContent-Type: application/zipData Raw: 50 4b 03 04 14 00 02 00 08 00 7b 9d 0f 3b 51 b7 76 de f5 1c 11 00 87 83 11 00 1b 00 00 00 4d 6f 64 53 6f 75 72 63 65 20 55 49 20 41 64 64 6f 6e 20 50 61 63 6b 2e 65 78 65 ec fd 07 5c 53 49 d7 38 8e df 90 00 91 62 50 41 51 51 51 b1 62 dd d8 10 0b 28 c1 8a a0 48 62 c1 82 14 43 44 40 48 04 0b 02 06 04 8c 88 5d b1 2b b2 36 ec 0d 3b 58 00 15 15 1b d6 55 2c ab 17 51 17 57 4a a8 e7 7f 66 6e 50 77 d7 7d 9e e7 7d df e7 fb 7e bf bf ff e7 89 1e ee dc a9 67 ce 9c 39 65 66 ee bd 2e 93 56 30 7c 86 61 04 08 00 0c 93 ce 70 3f 07 e6 9f ff f2 10 ea b7 3a 53 9f 39 5e ef 66 eb 74 de e8 9b ad c7 cb fd 43 ad 83 43 82 66 86 78 cd b6 f6 f6 0a 0c 0c 52 5a cf f0 b5 0e 51 05 5a fb 07 5a 3b b9 ba 5b cf 0e f2 f1 ed 66 6a 6a 64 a3 ab e3 57 d5 c8 3d 3b cc 6d aa ea a0 bb d5 82 aa 14 1a 6e 57 d5 1f af 6d ac e6 55 1d c6 6b 69 5f f3 aa 3d 78 f5 6b d8 a6 6a 3b 5e c7 f9 7b cb 49 fe 3f e3 e4 26 61 98 d1 3c 7d a6 fb c5 4f c3 ea e2 0a 18 11 cf 98 67 c0 30 93 f0 e6 3e 8f 76 b6 dd 4f 18 36 43 08 d6 f5 96 84 f5 38 3a 30 cc b7 2b e3 26 f8 7a a3 47 ff 9a 71 79 bf 5e bf 5e e8 6f 57 28 c3 1c a7 c4 e1 33 2b c2 98 7f df 0f f1 5c a6 f7 f7 c9 dd 94 be e1 4a bc f6 9a a8 43 68 d2 f7 9d e0 7e d6 0c 33 bd 5b 88 8f 97 d2 8b 61 56 34 d0 f5 bd 21 c2 d4 3f e6 43 6a 38 74 e3 b2 31 1b 0e 21 bd 56 e8 ea 0a fe 4b be 8c 6e 81 ba 8c 2b 30 9f c3 8f 11 8c 22 f9 42 42 43 bc 49 b6 30 8e 36 4c 38 5e 95 7f 6d 97 f9 cf ef 7f f5 e7 a1 f9 a0 fe e0 a9 8e 30 11 29 6d f1 af b3 46 62 ae 32 55 0f b7 34 d3 98 ee 19 34 84 49 18 2e 70 03 95 19 a8 4c 40 25 04 8b e1 21 0e 4c e1 10 1c 69 77 a9 a6 f7 61 4c 4f 94 ec 92 b9 d1 a4 d1 98 a4 f6 2d 61 12 24 26 89 92 37 5c 9c 1b c6 69 22 8a d5 be c5 8c a6 85 53 30 96 45 56 60 44 27 9d c7 89 4e 4a a5 a2 43 1e ac e6 b6 ad 0b 2b 3a 94 c9 bf 94 e0 62 96 5c 0e e2 bb 4b 8b 31 7d 2c 46 89 4e 8e f1 10 1d 72 61 f9 99 9a eb 98 82 25 c6 93 12 4b 73 30 dd 4d 74 48 62 c6 bf 84 d1 99 2f 85 a2 93 19 c6 39 89 92 12 b7 04 17 2d a2 88 cd a8 25 c5 82 04 89 b9 1b 87 88 09 58 8c 47 44 40 65 0e f7 d4 12 56 60 17 c1 8a 96 85 01 80 7a d1 04 50 fa c2 dc 5e 88 3d 96 8a cd c0 32 4a 0f 4d 84 89 82 27 cb 96 bc 21 b3 28 5b c2 0a 89 64 b4 70 c3 0c 30 77 82 0c eb 0a a6 75 69 7a 4f c0 80 0c f2 b9 0e cb ad 31 9f 9b 02 e4 db fb 0c c1 58 8b 09 b4 45 13 4c a7 ed 22 9d 38 92 78 62 fc b4 a9 e2 8c c9 d7 2e 99 31 9a d1 36 82 1d 39 48 46 cd 1d 77 ff bb 96 38 c5 a4 32 cd 78 3d 61 d9 25 3d a5 6b e2 1c 9e 18 ec 7b e7 62 72 e8 10 cd 2d ff 6b 24 3d d1 89 27 d4 08 cb 32 f5 94 fc 61 45 2d cb 32 05 ca 7a 9a db ae b1 d7 94 d6 45 66 65 99 66 2a 63 cd 63 f1 13 f5 6b 9e f8 71 82 a5 b3 3e 29 c1 d5 10 72 7d da d4 c9 97 04 64 b8 c7 8e d5 78 08 71 fc 7e f7 2f 23 e9 9a 16 04 01 f1 35 fe 17 59 82 4b 35 92 50 e3 2c dc a3 a7 34 b6 73 31 51 1a d8 5c 18 92 e0 2c b4
Source: ModSource UI Addon Pack.exe, 00000001.00000002.422163287.0000000002BD2000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://modsource.org
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://modsource.org/Files/SWG/Mods/ModSource_UI_Addon_Pack.ver
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://modsource.org/Files/SWG/Mods/ModSource_UI_Addon_Pack.ver/TIMEOUT=30000download
Source: ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://modsource.org/Files/SWG/Mods/ModSource_UI_Addon_Pack.ver/TIMEOUT=30000downloadhttp://users.on
Source: nsa449D.tmp.1.dr String found in binary or memory: http://modsource.org/Files/SWG/Mods/ModSource_UI_Addon_Pack.zip
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://modsource.org/Files/SWG/Mods/ModSource_UI_Addon_Pack.ziphttp://users.on.net/~anach/Files/SWG/
Source: ModSource UI Addon Pack.exe, ModSource UI Addon Pack.exe, 00000001.00000000.345573605.0000000000409000.00000008.00000001.01000000.00000007.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.0000000002BD2000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421438450.0000000000409000.00000004.00000001.01000000.00000007.sdmp, ModSource UI Addon Pack.exe, 00000001.00000003.410469484.0000000000792000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, Uninstall the ModSource UI Addon Pack.exe.1.dr, ModSource UI Addon Pack.exe.0.dr, nsa449D.tmp.1.dr String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, Uninstall the ModSource UI Addon Pack.exe.1.dr, ModSource UI Addon Pack.exe.0.dr, nsa449D.tmp.1.dr String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: ModSource UI Addon Pack.exe, 00000001.00000002.422163287.0000000002BD2000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://tassyp2p.optikal.net/viewtopic.php?f=45&t=837
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://unguilded.traumschmiede.com/Files/Mods/ModSource_UI_Addon_Pack.ver
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://unguilded.traumschmiede.com/Files/Mods/ModSource_UI_Addon_Pack.zip
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://users.on.net/~anach/Files/SWG/ModSource_UI_Addon_Pack.ver
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://users.on.net/~anach/Files/SWG/ModSource_UI_Addon_Pack.verhttp://unguilded.traumschmiede.com/F
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000002.346975161.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://users.on.net/~anach/Files/SWG/ModSource_UI_Addon_Pack.zip
Source: nsa449D.tmp.1.dr String found in binary or memory: http://www.modsource.org
Source: ModSource UI Addon Pack.exe, 00000001.00000002.421708783.000000000073C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.modsource.org/
Source: Mod-Source - Your Source for SWG Modding Stuff.lnk.1.dr String found in binary or memory: http://www.modsource.org/DC:
Source: ModSource UI Addon Pack.exe, 00000001.00000002.422163287.00000000026DC000.00000004.00000020.00020000.00000000.sdmp, ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, nsa449D.tmp.1.dr String found in binary or memory: http://www.modsource.orgopen
Source: ModSource UI Addon Pack.exe, 00000001.00000002.421708783.000000000073C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.modsource.orgw8
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/apple-touch-icon.png
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332365541.00000000006F5000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/contact
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332365541.00000000006F5000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/datenschutz
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/favicon-16x16.png
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/favicon-32x32.png
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/favicon.ico
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/gfx/emblem_b_xs.png
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332365541.00000000006F5000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/impressum
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332365541.00000000006F5000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332799089.00000000006F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/privacy
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.bplaced.net/safari-pinned-tab.svg
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknown DNS traffic detected: queries for: modsource.org
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global traffic HTTP traffic detected: GET /Files/SWG/Mods/ModSource_UI_Addon_Pack.ver HTTP/1.0Host: modsource.orgUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: global traffic HTTP traffic detected: GET /Files/SWG/Mods/ModSource_UI_Addon_Pack.ver HTTP/1.0Host: modsource.orgUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: global traffic HTTP traffic detected: GET /~anach/Files/SWG/ModSource_UI_Addon_Pack.ver HTTP/1.0Host: users.on.netUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: global traffic HTTP traffic detected: GET /Files/SWG/Mods/ModSource_UI_Addon_Pack.zip HTTP/1.0Host: modsource.orgUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: global traffic HTTP traffic detected: GET /Files/SWG/Mods/ModSource_UI_Addon_Pack.zip HTTP/1.0Host: modsource.orgUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: global traffic HTTP traffic detected: GET /~anach/Files/SWG/ModSource_UI_Addon_Pack.zip HTTP/1.0Host: users.on.netUser-Agent: NSISDL/1.2 (Mozilla)Accept: */*
Source: ModSource UI Addon Pack.exe, 00000001.00000002.421708783.00000000006BA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00404F1F GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_00404F1F
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00403225 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, 0_2_00403225
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00403225 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, 1_2_00403225
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_0040600A 0_2_0040600A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00404730 0_2_00404730
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00404730 1_2_00404730
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_0040600A 1_2_0040600A
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe ReversingLabs: Detection: 17%
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Virustotal: Detection: 19%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Jump to behavior
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Process created: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1800,i,4957897538365028636,534134650291675046,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Process created: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1800,i,4957897538365028636,534134650291675046,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: ModSource UI Addon Pack Silent Updater.lnk.1.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe
Source: Uninstall the ModSource UI Addon Pack.lnk.1.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.exe
Source: ModSource UI Addon Pack Updater.lnk.1.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe
Source: Readme ModSource UI Addon Pack.lnk.1.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html
Source: Pre-NGE UI Changelog.lnk.1.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Changelog_PreNGE_UI.txt
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ModSource UI Addon Pack Silent Updater.lnk Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File created: C:\Users\user\AppData\Local\Temp\nsb13F7.tmp Jump to behavior
Source: classification engine Classification label: sus32.winEXE@29/101@12/8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00402012 CoCreateInstance,MultiByteToWideChar, 0_2_00402012
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00404275 GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA, 0_2_00404275
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Automated click: Next >
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\ModSource UI Addon Pack Uninstall.log Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Ui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_chat_window_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_mfd_status_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_all_targets.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_targets_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_secondary_targets_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_pet.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_sml_group_window.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_radar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_location_display.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_exp_mon_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_collections.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_buttonbar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space_buttonbar.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_ground_hud_toolbar_skinned.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_hud_space_toolbar.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_styles.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_palette_ground.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_palette_space.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Ui\ui_pda_net_status.inc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Texture Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\heavyweapons_reticule.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\reticle_readme.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_activate.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_attack.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_big.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_crafting.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_deactivate.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_death_blow.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_default.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drag_bad.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drag_scroll.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_drop.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_eat.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_equip.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_hourglass.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_intended_attack.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_mission_details.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_move.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_open.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_pickup.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_hor.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_se.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_sw.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_resize_vert.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_stop_talk.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_talk.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_throw.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_trade_accepted.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_trade_start.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_unequip.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_cursor_use.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_target_inactive.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Texture\ui_background_arrow.dds Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\readme_BattleBackground.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Backup\Sample Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_incoming_mail.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_fusioncutter_end.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_toggle_mouse_mode.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_use_toolbar.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_popup.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_arrow_back.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_arrow_forward.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_button_confirm.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_dialog_warning.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_increment_big.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_menu_close.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_rollover.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_info.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_select_rotate.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_open_metal_can_cntner.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\item_close_metal_can_cntner.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Sample\ui_negative.wav Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Changelog_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme_Anachs_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Readme.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Web.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Update.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Icons\Uninstall.ico Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Directory created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.exe Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\GoogleUpdater Jump to behavior
Source: Binary string: q.pdB source: ModSource UI Addon Pack.exe.0.dr, ModSource UI Addon Pack.zip.0.dr
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405D61 GetModuleHandleA,LoadLibraryA,GetProcAddress, 0_2_00405D61
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Local\Temp\nsk44DC.tmp\StartMenu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Local\Temp\nsk44DC.tmp\nsDialogs.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File created: C:\Users\user\AppData\Local\Temp\nsb13F9.tmp\ZipDLL.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Local\Temp\nsk44DC.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File created: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe File created: C:\Users\user\AppData\Local\Temp\nsb13F9.tmp\NSISdl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Local\Temp\nsk44DC.tmp\NSISdl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\reticle_readme.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\readme_BattleBackground.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme_Anachs_PreNGE_UI.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Program Files\StarWarsGalaxies\ModSource UI Addon Pack Uninstall.log Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ModSource UI Addon Pack Silent Updater.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack\ModSource UI Addon Pack Updater.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack\Readme ModSource UI Addon Pack.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack\Mod-Source - Your Source for SWG Modding Stuff.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModSource UI Addon Pack\Pre-NGE UI Changelog.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ModSource UI Addon Pack Silent Updater.lnk Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Dropped PE file which has not been started: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Updater\ModSource UI Addon Pack Auto Updater Silent.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Dropped PE file which has not been started: C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Uninstall the ModSource UI Addon Pack.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405368 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_00405368
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405D3A FindFirstFileA,FindClose, 0_2_00405D3A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00402630 FindFirstFileA, 0_2_00402630
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00405368 CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 1_2_00405368
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00405D3A FindFirstFileA,FindClose, 1_2_00405D3A
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Code function: 1_2_00402630 FindFirstFileA, 1_2_00402630
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332433511.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.344668347.00000000006ED000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe, 00000000.00000003.332819641.00000000006ED000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405D61 GetModuleHandleA,LoadLibraryA,GetProcAddress, 0_2_00405D61
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Program Files\StarWarsGalaxies\Mods\ModSource UI Addon Pack\Documentation\Readme ModSource UI Addon Pack.html Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ModSource UI Addon Pack\ModSource UI Addon Pack.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader28.22066.19106.30146.exe Code function: 0_2_00405A65 GetVersion,GetSystemDirectoryA,GetWindowsDirectoryA,SHGetSpecialFolderLocation,SHGetPathFromIDListA,CoTaskMemFree,lstrcatA,lstrlenA, 0_2_00405A65
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs