Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_0040699E FindFirstFileW,FindClose, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_0040290B FindFirstFileW, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_004089F8 FindFirstFileExW, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_00406715 FindFirstFileExW, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00405809 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,ExitProcess,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00406D5F |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_00410371 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F08B7 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F0A34 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_0040CBD1 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023C7240 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023CC2F0 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023C7E58 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023C7588 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023C4C7B |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_056DCC51 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_056DC1BC |
Source: unknown | Process created: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process created: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe "C:\Users\user~1\AppData\Local\Temp\rtvzitvzef.exe" C:\Users\user~1\AppData\Local\Temp\ggbdhaflcbm.cer |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process created: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe C:\Users\user~1\AppData\Local\Temp\rtvzitvzef.exe |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process created: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe "C:\Users\user~1\AppData\Local\Temp\rtvzitvzef.exe" C:\Users\user~1\AppData\Local\Temp\ggbdhaflcbm.cer |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process created: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe C:\Users\user~1\AppData\Local\Temp\rtvzitvzef.exe |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,ExitProcess,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_00410AA4 push ecx; ret |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_0040D2E1 push ecx; ret |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_023CD286 push esi; retf |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_056D5278 pushfd ; iretd |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_0040699E FindFirstFileW,FindClose, |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_0040290B FindFirstFileW, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_004089F8 FindFirstFileExW, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_00406715 FindFirstFileExW, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F005F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F0109 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F013E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_009F017B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_004018F8 SetUnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_0040636B IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_00401BF3 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 1_2_00401796 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_00401E16 SetUnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_00401C83 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_004060A4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Code function: 3_2_00401F2A SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Source: C:\Users\user\Desktop\Tender_QUOTATION__LH22000309AA2023.exe | Code function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,ExitProcess,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Source: C:\Users\user\AppData\Local\Temp\rtvzitvzef.exe | Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |