Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001D2012 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
0_2_001D2012 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0027D2B0 CreateDirectoryA,FindFirstFileA,CreateDirectoryA,CopyFileA,FindNextFileA,FindClose,GetLastError,GetLastError, |
0_2_0027D2B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002633B0 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
0_2_002633B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002313F0 FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
0_2_002313F0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00231A60 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, |
0_2_00231A60 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00283B20 FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
0_2_00283B20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001EFC1D FindFirstFileExW, |
0_2_001EFC1D |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001D1F8C FindClose,FindFirstFileExW,GetLastError, |
0_2_001D1F8C |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.5 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F9588 |
0_2_001F9588 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001E001D |
0_2_001E001D |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002E40A0 |
0_2_002E40A0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00298080 |
0_2_00298080 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002D20C0 |
0_2_002D20C0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0022E120 |
0_2_0022E120 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00222100 |
0_2_00222100 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002D81A0 |
0_2_002D81A0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002361D0 |
0_2_002361D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002A4220 |
0_2_002A4220 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002B4220 |
0_2_002B4220 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00218200 |
0_2_00218200 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001AA2C0 |
0_2_001AA2C0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028A2D0 |
0_2_0028A2D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001E035F |
0_2_001E035F |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00290350 |
0_2_00290350 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0027C3E0 |
0_2_0027C3E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002463D0 |
0_2_002463D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002A0520 |
0_2_002A0520 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F47AD |
0_2_001F47AD |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0026E800 |
0_2_0026E800 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002DC8D0 |
0_2_002DC8D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001DA918 |
0_2_001DA918 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001DC950 |
0_2_001DC950 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002509B0 |
0_2_002509B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002749B0 |
0_2_002749B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0024E9E0 |
0_2_0024E9E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0026CAA0 |
0_2_0026CAA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00294AA0 |
0_2_00294AA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00238A80 |
0_2_00238A80 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002E4AE0 |
0_2_002E4AE0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002D6B30 |
0_2_002D6B30 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00230BA0 |
0_2_00230BA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00284B90 |
0_2_00284B90 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F8BA0 |
0_2_001F8BA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0023CBF0 |
0_2_0023CBF0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00294CD0 |
0_2_00294CD0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028CD20 |
0_2_0028CD20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F8E20 |
0_2_001F8E20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00268E70 |
0_2_00268E70 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00246EA0 |
0_2_00246EA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0023AEC0 |
0_2_0023AEC0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0024AED0 |
0_2_0024AED0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002BAF30 |
0_2_002BAF30 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00294F70 |
0_2_00294F70 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028CFC0 |
0_2_0028CFC0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00295070 |
0_2_00295070 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002A1040 |
0_2_002A1040 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0022D0B0 |
0_2_0022D0B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002970E0 |
0_2_002970E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00241130 |
0_2_00241130 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002E3160 |
0_2_002E3160 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001D7190 |
0_2_001D7190 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002332B0 |
0_2_002332B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002DF280 |
0_2_002DF280 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0025F2D0 |
0_2_0025F2D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0029D320 |
0_2_0029D320 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0029F360 |
0_2_0029F360 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0025D450 |
0_2_0025D450 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00293450 |
0_2_00293450 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002BF450 |
0_2_002BF450 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002A54A0 |
0_2_002A54A0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00219490 |
0_2_00219490 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028B500 |
0_2_0028B500 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001CF570 |
0_2_001CF570 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002AF5E0 |
0_2_002AF5E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002A7630 |
0_2_002A7630 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0021F730 |
0_2_0021F730 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0025B770 |
0_2_0025B770 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0027B7E0 |
0_2_0027B7E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002977F0 |
0_2_002977F0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028D7D0 |
0_2_0028D7D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00255880 |
0_2_00255880 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001AB8E0 |
0_2_001AB8E0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002B18D0 |
0_2_002B18D0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00295960 |
0_2_00295960 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00231A60 |
0_2_00231A60 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001EDA74 |
0_2_001EDA74 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002E5A40 |
0_2_002E5A40 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0027DA80 |
0_2_0027DA80 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028FBA0 |
0_2_0028FBA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00223C3D |
0_2_00223C3D |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00297CA0 |
0_2_00297CA0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001A9C90 |
0_2_001A9C90 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002E3CF0 |
0_2_002E3CF0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00247D20 |
0_2_00247D20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00243D70 |
0_2_00243D70 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00241E40 |
0_2_00241E40 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00295EB0 |
0_2_00295EB0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00233ED0 |
0_2_00233ED0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0029DF20 |
0_2_0029DF20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00281F80 |
0_2_00281F80 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0028BFC0 |
0_2_0028BFC0 |
Source: ZtQY1K6aTi.exe, ZtQY1K6aTi.exe, 00000000.00000000.1976264611.00000000002FA000.00000002.00000001.01000000.00000003.sdmp, ZtQY1K6aTi.exe, 00000000.00000002.3254255271.00000000046F2000.00000004.00000020.00020000.00000000.sdmp, ZtQY1K6aTi.exe, 00000000.00000002.3253798896.00000000002FA000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q); |
Source: ZtQY1K6aTi.exe, 00000000.00000000.1976264611.00000000002FA000.00000002.00000001.01000000.00000003.sdmp, ZtQY1K6aTi.exe, 00000000.00000002.3254255271.00000000046F2000.00000004.00000020.00020000.00000000.sdmp, ZtQY1K6aTi.exe, 00000000.00000002.3253798896.00000000002FA000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: UPDATE %Q.%s SET sql = sqlite_rename_table(sql, %Q), tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger'); |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: gpedit.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: dssec.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: dsuiext.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: dsrole.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: logoncli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: ntdsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: authz.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001D2012 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
0_2_001D2012 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_0027D2B0 CreateDirectoryA,FindFirstFileA,CreateDirectoryA,CopyFileA,FindNextFileA,FindClose,GetLastError,GetLastError, |
0_2_0027D2B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002633B0 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
0_2_002633B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002313F0 FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
0_2_002313F0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00231A60 SHGetFolderPathA,FindFirstFileA,FindNextFileA,FindClose,CreateDirectoryA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CreateDirectoryA,CreateDirectoryA,CopyFileA,CopyFileA, |
0_2_00231A60 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00283B20 FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
0_2_00283B20 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001EFC1D FindFirstFileExW, |
0_2_001EFC1D |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001D1F8C FindClose,FindFirstFileExW,GetLastError, |
0_2_001D1F8C |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FA082 mov eax, dword ptr fs:[00000030h] |
0_2_001FA082 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FA082 mov ecx, dword ptr fs:[00000030h] |
0_2_001FA082 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002709B0 mov eax, dword ptr fs:[00000030h] |
0_2_002709B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F9588 mov eax, dword ptr fs:[00000030h] |
0_2_001F9588 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F9588 mov eax, dword ptr fs:[00000030h] |
0_2_001F9588 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F9588 mov eax, dword ptr fs:[00000030h] |
0_2_001F9588 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001F9588 mov ecx, dword ptr fs:[00000030h] |
0_2_001F9588 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FDA50 mov eax, dword ptr fs:[00000030h] |
0_2_001FDA50 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FDA50 mov eax, dword ptr fs:[00000030h] |
0_2_001FDA50 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00264130 mov eax, dword ptr fs:[00000030h] |
0_2_00264130 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00270420 mov ecx, dword ptr fs:[00000030h] |
0_2_00270420 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FA61F mov eax, dword ptr fs:[00000030h] |
0_2_001FA61F |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FA61F mov eax, dword ptr fs:[00000030h] |
0_2_001FA61F |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_001FA61F mov eax, dword ptr fs:[00000030h] |
0_2_001FA61F |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_002332B0 mov eax, dword ptr fs:[00000030h] |
0_2_002332B0 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00273630 mov eax, dword ptr fs:[00000030h] |
0_2_00273630 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: 0_2_00265A70 mov eax, dword ptr fs:[00000030h] |
0_2_00265A70 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetACP,IsValidCodePage,GetLocaleInfoW, |
0_2_001F2B48 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW, |
0_2_001F2D4D |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: EnumSystemLocalesW, |
0_2_001F2DF4 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: EnumSystemLocalesW, |
0_2_001F2E3F |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: EnumSystemLocalesW, |
0_2_001F2EDA |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
0_2_001F2F65 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW, |
0_2_001F31B8 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: EnumSystemLocalesW, |
0_2_001EB1A3 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_001F32E1 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW, |
0_2_001F33E7 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
0_2_001F34BD |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoW, |
0_2_001EB726 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: CreateDirectoryA,RegOpenKeyExA,RegQueryValueExA,RegCloseKey,GetCurrentHwProfileA,GetModuleHandleExA,GetModuleFileNameA,RegOpenKeyExA,RegQueryValueExA,RegCloseKey,GetComputerNameA,GetUserNameA,GetDesktopWindow,GetWindowRect,GetUserDefaultLocaleName,GetKeyboardLayoutList,GetKeyboardLayoutList,LocalAlloc,GetKeyboardLayoutList,GetLocaleInfoA,LocalFree,GetLocalTime,GetSystemTime,GetTimeZoneInformation,TzSpecificLocalTimeToSystemTime,RegOpenKeyExA,RegQueryValueExA,RegCloseKey,GetSystemInfo,GlobalMemoryStatusEx,EnumDisplayDevicesA,EnumDisplayDevicesA,CreateToolhelp32Snapshot,Process32First,Process32Next,Process32Next,CloseHandle,RegOpenKeyExA,RegEnumKeyExA,wsprintfA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,RegCloseKey, |
0_2_0027DA80 |
Source: C:\Users\user\Desktop\ZtQY1K6aTi.exe |
Code function: GetLocaleInfoEx,FormatMessageA, |
0_2_001D1D84 |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions |
Registry value created: Exclusions_Extensions 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender |
Registry value created: DisableAntiSpyware 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender |
Registry value created: DisableRoutinelyTakingAction 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableBehaviorMonitoring 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableOnAccessProtection 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableScanOnRealtimeEnable 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableRealtimeMonitoring 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableIOAVProtection 1 |
Jump to behavior |
Source: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\group policy objects\{6BB86D62-6074-413F-AC7A-F6E5212F3B22}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection |
Registry value created: DisableRawWriteNotification 1 |
Jump to behavior |