Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02589370 __EH_prolog,CryptGenRandom,CryptCreateHash,GetLastError,CryptSetHashParam,GetLastError, | 3_2_02589370 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_0258864E __EH_prolog,CryptGenRandom,CryptGenRandom,GetLastError,CryptGenRandom,GetLastError,CryptEncrypt,GetLastError,EnterCriticalSection,LeaveCriticalSection,Sleep,EnterCriticalSection,LeaveCriticalSection,EnterCriticalSection,LeaveCriticalSection,CryptDestroyHash,CryptDestroyKey,CryptDestroyHash,CryptDestroyKey, | 3_2_0258864E |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02581980 CryptDestroyKey,CryptImportKey,GetLastError, | 3_2_02581980 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_0258755C __EH_prolog,CryptAcquireContextA,CryptCreateHash,GetLastError,CryptHashData,GetLastError,CryptDestroyHash,CryptReleaseContext, | 3_2_0258755C |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025830AC CryptDestroyKey, | 3_2_025830AC |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025826F3 CloseHandle,CreateFileW,CloseHandle,CryptGenRandom,GetLastError, | 3_2_025826F3 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025816BA CryptDestroyKey, | 3_2_025816BA |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02581A70 CryptDestroyKey, | 3_2_02581A70 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025817ED CryptEncrypt,GetLastError, | 3_2_025817ED |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02596BA6 CryptDestroyKey, | 3_2_02596BA6 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02588C0C CryptDestroyHash,CryptDestroyKey, | 3_2_02588C0C |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025836F3 __EH_prolog,CryptAcquireContextA,CryptReleaseContext, | 3_2_025836F3 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025816F5 CryptSetKeyParam,GetLastError, | 3_2_025816F5 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02582E25 CryptGenRandom,GetLastError, | 3_2_02582E25 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02583DA7 CryptDestroyKey,CryptReleaseContext, | 3_2_02583DA7 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02589298 CryptGetKeyParam,GetLastError, | 3_2_02589298 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025837FF __EH_prolog,CryptDestroyKey,CryptReleaseContext, | 3_2_025837FF |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02582273 __EH_prolog,GetFileAttributesExW,GetLastError,SetFileAttributesW,CloseHandle,MoveFileExW,GetLastError,CloseHandle,CreateFileW,CloseHandle,CryptGenRandom,GetLastError,CryptEncrypt,GetLastError,GetSystemTimeAsFileTime,CloseHandle,SetFileAttributesW,CloseHandle,GetLastError, | 3_2_02582273 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02587B8A __EH_prolog,CryptGetHashParam,GetLastError, | 3_2_02587B8A |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02596B93 CryptReleaseContext, | 3_2_02596B93 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02588C2C __EH_prolog,EnterCriticalSection,CryptAcquireContextA,CryptReleaseContext,CryptReleaseContext,CryptReleaseContext,CryptImportKey,GetLastError,CryptDestroyKey,LeaveCriticalSection, | 3_2_02588C2C |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02587B7C CryptDestroyHash, | 3_2_02587B7C |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025892E4 CryptHashData,GetLastError, | 3_2_025892E4 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025836C6 CryptReleaseContext, | 3_2_025836C6 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025836E3 CryptReleaseContext, | 3_2_025836E3 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_0258932B CryptGetHashParam,GetLastError, | 3_2_0258932B |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025890B5 CryptGenRandom,GetLastError, | 3_2_025890B5 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_0040200D CryptMsgCountersignEncoded,LoadMenuA,CreateMenu,LoadMenuA,LoadBitmapA,AppendMenuA,LoadMenuA,CryptMsgDuplicate,GetStockObject,GetStockObject,SelectObject,GetStockObject,GetObjectA,SendMessageA,OffsetRect,GetPixel,BeginPaint,DrawTextA,DefWindowProcA,BeginPaint,GetClientRect,DrawTextA,EndPaint,PostQuitMessage,DefWindowProcA,GetDlgItem,CreateWindowExA,BeginPaint,SetWindowPos,SetWindowLongA,BeginPaint,MultiByteToWideChar,BeginPaint,MultiByteToWideChar,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,GetWindowRect,GetCursorPos,PtInRect,SendMessageA,GetScrollPos,SetScrollPos,InvalidateRect,BeginPaint,LockResource,GetClientRect,DrawTextA,EndPaint,MoveWindow,SetFocus,FreeResource,PostQuitMessage,GetDC,GetTextMetricsA,ReleaseDC,GetSystemMetrics,CreateWindowExA,LoadStringA,FindResourceA,LoadResource,LockResource,CharNextA,SetScrollRange,SetScrollPos,SendMessageA,GetLastError,CreateWindowExA,ImageList_Create,SendMessageA,SendMessageA,ICLocate,ICOpen,ICSendMessage,ICClose,ICInfo,ICGetInfo,SendM | 3_1_0040200D |
Source: powershell.exe | String found in binary or memory: file:// |
Source: powershell.exe | String found in binary or memory: file:/// |
Source: wscript.exe | String found in binary or memory: file:///c:/ground-label-004117618.doc-2161f8cf7b6c1a1a3a6fdc41083566a5.wsf |
Source: wscript.exe | String found in binary or memory: file:///c:/users/admin/appdata/local/temp/a1.exe |
Source: wscript.exe | String found in binary or memory: file:///c:/users/admin/appdata/local/temp/a2.exe |
Source: wscript.exe | String found in binary or memory: file:///c:/users/admin/appdata/local/temp/a2.exe9 |
Source: powershell.exe | String found in binary or memory: file:///c:/windows/syswow64/windowspowershell/v1.0/a |
Source: mshta.exe | String found in binary or memory: file:///c:/windows/syswow64/windowspowershell/v1.0/powershell.exe |
Source: wscript.exe, a1.exe, powershell.exe | String found in binary or memory: http:// |
Source: a1.exe | String found in binary or memory: http://109.234.36.12 |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/ |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/checkupdate |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/checkupdateel |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/checkupdatenet |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/checkupdates |
Source: a1.exe | String found in binary or memory: http://109.234.36.12/checkupdatetemp |
Source: a1.exe | String found in binary or memory: http://109.234.36.12b8%d1s%27kf%1 |
Source: regsvr32.exe | String found in binary or memory: http://15.241.211.182 |
Source: regsvr32.exe | String found in binary or memory: http://15.241.211.182/ |
Source: regsvr32.exe | String found in binary or memory: http://15.241.211.182/n |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php |
Source: a2.exe, powershell.exe, regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php2 |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:al |
Source: a2.exe | String found in binary or memory: http://185.117.72.90/upload.php:al$m |
Source: a2.exe | String found in binary or memory: http://185.117.72.90/upload.php:al% |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:al2 |
Source: powershell.exe, regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:al940196953103877199811371834197299886690010229547993815721647414299 |
Source: a2.exe, powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:al:mainanti |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:al:mainantih |
Source: a2.exe | String found in binary or memory: http://185.117.72.90/upload.php:al; |
Source: a2.exe, powershell.exe, regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:ald10d:1:dd10ddd11d:0:dd11ddd12d:1:dd12ddd13d:1:dd13ddd14d:1:dd14ddd |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:ali |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:alj |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:alk |
Source: a2.exe, powershell.exe, regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:alload.php:aload.php:aload.php:aload.php:aload.php:aload.php:aload.p |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:aln |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:alo |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:als |
Source: powershell.exe | String found in binary or memory: http://185.117.72.90/upload.php:alx |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.php:al~~7 |
Source: a2.exe | String found in binary or memory: http://185.117.72.90/upload.phpll |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload.phpr |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload2.php |
Source: a2.exe | String found in binary or memory: http://185.117.72.90/upload2.php1000 |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload2.php34320m |
Source: regsvr32.exe | String found in binary or memory: http://185.117.72.90/upload2.phpl |
Source: a1.exe | String found in binary or memory: http://91.210.166.51 |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/ |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/checkupdate |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/checkupdate& |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/checkupdated |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/checkupdatemicrosoft |
Source: a1.exe | String found in binary or memory: http://91.210.166.51/checkupdater |
Source: a1.exe | String found in binary or memory: http://91.210.166.5100 |
Source: wscript.exe | String found in binary or memory: http://baltasmenulis.lt/counter/?i=lrqadziqanpqacxla4p__r285amki81__3rpkyws4ham4nv8qlhokfhomht9fzlwl |
Source: powershell.exe | String found in binary or memory: http://cdp1.public-trust.com/crl/omniroot2025.crl0 |
Source: powershell.exe | String found in binary or memory: http://crl.usertrust.com/utn-userfirst-object.crl0) |
Source: powershell.exe | String found in binary or memory: http://cybertrust.omniroot.com/repository.cfm0 |
Source: a1.exe | String found in binary or memory: http://en.wikipedia.org/wiki/advanced_encryption_standard |
Source: a1.exe | String found in binary or memory: http://en.wikipedia.org/wiki/rsa_(cryptosystem) |
Source: powershell.exe | String found in binary or memory: http://go.microsof |
Source: wscript.exe | String found in binary or memory: http://kidsgalaxy.fr/ |
Source: wscript.exe | String found in binary or memory: http://kidsgalaxy.fr/counter/?i=lrqadziqanpqacxla4p__r285amki81__3rpkyws4ham4nv8qlhokfhomht9fzlwlztl |
Source: wscript.exe | String found in binary or memory: http://med-lex.com/ |
Source: wscript.exe | String found in binary or memory: http://med-lex.com/counter/?a=1nfzcr8ogaeev4nmxjbypnabevwbgpukhc&m=binging&i=lrqadziqanpqacxla4p__r2 |
Source: a1.exe | String found in binary or memory: http://post |
Source: powershell.exe | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: powershell.exe | String found in binary or memory: http://schemas.datacontract.org/2004/07/system.management.automation |
Source: powershell.exe | String found in binary or memory: http://schemas.datacontract.org/2004/07/system.management.automationl |
Source: powershell.exe | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: wscript.exe | String found in binary or memory: http://www.kidsgalaxy.fr/ |
Source: wscript.exe | String found in binary or memory: http://www.kidsgalaxy.fr/6 |
Source: wscript.exe | String found in binary or memory: http://www.kidsgalaxy.fr/counter/?i=lrqadziqanpqacxla4p__r285amki81__3rpkyws4ham4nv8qlhokfhomht9fzlw |
Source: powershell.exe | String found in binary or memory: http://www.usertrust.com1 |
Source: regsvr32.exe | String found in binary or memory: https:// |
Source: regsvr32.exe | String found in binary or memory: https://fpdownload.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_24_acti |
Source: wscript.exe | String found in binary or memory: https://login.live.com |
Source: a1.exe | String found in binary or memory: https://www.torproject.org/download/download-easy.html |
Source: C:\Windows\SysWOW64\wscript.exe | Code function: 0_2_06BAB78A push es; ret | 0_2_06BAB790 |
Source: C:\Windows\SysWOW64\wscript.exe | Code function: 0_2_06BAACA3 push es; retf | 0_2_06BAACA4 |
Source: C:\Windows\SysWOW64\wscript.exe | Code function: 0_2_06BAED6B push es; iretd | 0_2_06BAED6C |
Source: C:\Windows\SysWOW64\wscript.exe | Code function: 0_2_06BAB17D push ecx; ret | 0_2_06BAB17E |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_004021D8 push 00402210h; ret | 5_2_00402208 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF8B38 push 00AF8CA0h; ret | 5_2_00AF8C98 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B20648 push 00B206D8h; ret | 5_2_00B206D0 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF0584 push ecx; retf | 5_2_00AF0590 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE6588 push 00AE6677h; ret | 5_2_00AE666F |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2BF58 push ecx; mov dword ptr [esp], FFFFFFFFh | 5_2_00B2BF5B |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AEBF64 push 00AEBF97h; ret | 5_2_00AEBF8F |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B0A7F0 push 00B0A81Ch; ret | 5_2_00B0A814 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF18C4 push 00AF18F0h; ret | 5_2_00AF18E8 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF181F push 00AF18BAh; ret | 5_2_00AF18B2 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE6CEC push 00AE6D18h; ret | 5_2_00AE6D10 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AEB6B8 push 00AEB6E4h; ret | 5_2_00AEB6DC |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AFA74C push 00AFA778h; ret | 5_2_00AFA770 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B07CE4 push 00B07D71h; ret | 5_2_00B07D69 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B0DDC4 push 00B0DDF0h; ret | 5_2_00B0DDE8 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AED08B push 00AED124h; ret | 5_2_00AED11C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AED8D4 push 00AED8FDh; ret | 5_2_00AED8F5 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF1914 push 00AF1946h; ret | 5_2_00AF193E |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B0D88C push 00B0D8CEh; ret | 5_2_00B0D8C6 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2CAF4 push 00B2CB39h; ret | 5_2_00B2CB31 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF06C0 push ss; ret | 5_2_00AF06C5 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B0DDFC push 00B0DE28h; ret | 5_2_00B0DE20 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B20F80 push 00B20FD7h; ret | 5_2_00B20FCF |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B160E4 push 00B16126h; ret | 5_2_00B1611E |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF2B70 push 00AF2B9Ch; ret | 5_2_00AF2B94 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF1878 push 00AF18BAh; ret | 5_2_00AF18B2 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE8198 push 00AE81C4h; ret | 5_2_00AE81BC |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025897BF __EH_prolog,FindFirstFileW,__wcsicoll,__wcsicoll,FindNextFileW,FindClose, | 3_2_025897BF |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02587314 FindFirstFileW,FindClose, | 3_2_02587314 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_0040200D CryptMsgCountersignEncoded,LoadMenuA,CreateMenu,LoadMenuA,LoadBitmapA,AppendMenuA,LoadMenuA,CryptMsgDuplicate,GetStockObject,GetStockObject,SelectObject,GetStockObject,GetObjectA,SendMessageA,OffsetRect,GetPixel,BeginPaint,DrawTextA,DefWindowProcA,BeginPaint,GetClientRect,DrawTextA,EndPaint,PostQuitMessage,DefWindowProcA,GetDlgItem,CreateWindowExA,BeginPaint,SetWindowPos,SetWindowLongA,BeginPaint,MultiByteToWideChar,BeginPaint,MultiByteToWideChar,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,GetWindowRect,GetCursorPos,PtInRect,SendMessageA,GetScrollPos,SetScrollPos,InvalidateRect,BeginPaint,LockResource,GetClientRect,DrawTextA,EndPaint,MoveWindow,SetFocus,FreeResource,PostQuitMessage,GetDC,GetTextMetricsA,ReleaseDC,GetSystemMetrics,CreateWindowExA,LoadStringA,FindResourceA,LoadResource,LockResource,CharNextA,SetScrollRange,SetScrollPos,SendMessageA,GetLastError,CreateWindowExA,ImageList_Create,SendMessageA,SendMessageA,ICLocate,ICOpen,ICSendMessage,ICClose,ICInfo,ICGetInfo,SendM | 3_1_0040200D |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B29E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B29E80 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE5840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 5_2_00AE5840 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 5_2_00B2B32C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 5_2_00B2B08C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B163DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B163DC |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B2B420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 9_2_008CB32C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_00885840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 9_2_00885840 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008D1E74 FindFirstFileW,6E15D4C0,6E15DFB0,6E15D4C0,FindNextFileW,FindClose,FindFirstFileW,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW,FindNextFileW,FindClose,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW, | 9_2_008D1E74 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008CB420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 9_2_008CB08C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008B63DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008B63DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C9E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008C9E80 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 12_2_0104B32C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010363DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_010363DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01005840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 12_2_01005840 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_0104B420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01051E74 FindFirstFileW,6E15D4C0,6E15DFB0,6E15D4C0,FindNextFileW,FindClose,FindFirstFileW,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW,FindNextFileW,FindClose,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW, | 12_2_01051E74 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01049E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_01049E80 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 12_2_0104B08C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B252A0 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 5_2_00B252A0 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B1CA28 NtSuspendProcess,OpenProcess,NtSuspendProcess,CloseHandle, | 5_2_00B1CA28 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AF23CC NtQueryInformationProcess, | 5_2_00AF23CC |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B27E10 RegOpenKeyExW,RegCreateKeyW,RegCloseKey,RegOpenKeyExW,NtSetValueKey,RegCloseKey, | 5_2_00B27E10 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B27D48 RegOpenKeyExW,NtDeleteValueKey,RegCloseKey, | 5_2_00B27D48 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B258B8 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle,DeleteFileW, | 5_2_00B258B8 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B24588 CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtWriteVirtualMemory,GetCurrentProcess,NtUnmapViewOfSection,GetThreadContext,SetThreadContext,ResumeThread,VirtualFree,TerminateProcess,CloseHandle,CloseHandle,CloseHandle, | 5_2_00B24588 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B27C6C RegOpenKeyExW,NtQueryValueKey,RegCloseKey, | 5_2_00B27C6C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2349C CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle, | 5_2_00B2349C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B240E8 OpenProcess,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,CloseHandle,CloseHandle,CloseHandle, | 5_2_00B240E8 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B24D70 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 5_2_00B24D70 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE6B92 NtdllDefWindowProc_A, | 5_2_00AE6B92 |
Source: C:\Windows\System32\conhost.exe | Code function: 8_2_00007FF6C8BE1010 EventRegister,EventSetInformation,GetCommandLineW,wcstok_s,wcstoul,wcstok_s,NtQueryVolumeInformationFile,LoadLibraryExW,GetProcAddress,SetProcessShutdownParameters,RtlExitUserThread,wcsncmp,wcsncmp,FreeLibrary,GetLastError,GetLastError,GetLastError,EventUnregister, | 8_2_00007FF6C8BE1010 |
Source: C:\Windows\System32\conhost.exe | Code function: 8_2_00007FF6C8BE1300 RtlOpenCurrentUser,RtlInitUnicodeString,NtOpenKey,RtlInitUnicodeString,GetProcessHeap,HeapAlloc,NtQueryValueKey,GetProcessHeap,HeapFree,NtClose,NtClose, | 8_2_00007FF6C8BE1300 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_00892484 NtWow64ReadVirtualMemory64, | 9_2_00892484 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_0089263C NtWow64ReadVirtualMemory64,NtWow64ReadVirtualMemory64,NtWow64ReadVirtualMemory64,NtWow64ReadVirtualMemory64, | 9_2_0089263C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008923F8 NtWow64QueryInformationProcess64, | 9_2_008923F8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C4588 CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtWriteVirtualMemory,GetCurrentProcess,NtUnmapViewOfSection,GetThreadContext,SetThreadContext,ResumeThread,VirtualFree,TerminateProcess,CloseHandle,CloseHandle,CloseHandle, | 9_2_008C4588 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C0CFC GetModuleHandleA,GetProcAddress,VirtualAlloc,NtQuerySystemInformation,VirtualFree,VirtualFree, | 9_2_008C0CFC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008923CC NtQueryInformationProcess, | 9_2_008923CC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C7C6C 6E135A60,NtQueryValueKey,RegCloseKey, | 9_2_008C7C6C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C7E10 6E135A60,6E15DB00,RegCloseKey,6E135A60,NtSetValueKey,RegCloseKey, | 9_2_008C7E10 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C58B8 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle,6E15D4C0, | 9_2_008C58B8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C4D70 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 9_2_008C4D70 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008BCA28 NtSuspendProcess,OpenProcess,NtSuspendProcess,CloseHandle, | 9_2_008BCA28 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C52A0 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 9_2_008C52A0 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008D54DC NtdllDefWindowProc_A,NtdllDefWindowProc_A, | 9_2_008D54DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008D543C NtdllDefWindowProc_A,NtdllDefWindowProc_A, | 9_2_008D543C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C40E8 OpenProcess,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,CloseHandle,CloseHandle,CloseHandle, | 9_2_008C40E8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C349C CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle, | 9_2_008C349C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C7D48 6E135A60,NtDeleteValueKey,RegCloseKey, | 9_2_008C7D48 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0103CA28 NtSuspendProcess,OpenProcess,NtSuspendProcess,CloseHandle, | 12_2_0103CA28 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01044588 CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtWriteVirtualMemory,GetCurrentProcess,NtUnmapViewOfSection,GetThreadContext,SetThreadContext,ResumeThread,VirtualFree,TerminateProcess,CloseHandle,CloseHandle,CloseHandle, | 12_2_01044588 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104349C CreateProcessW,CreateProcessW,Sleep,TerminateProcess,CloseHandle,CloseHandle,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle, | 12_2_0104349C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0105543C NtdllDefWindowProc_A,NtdllDefWindowProc_A, | 12_2_0105543C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01047C6C 6E135A60,NtQueryValueKey,RegCloseKey, | 12_2_01047C6C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010452A0 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 12_2_010452A0 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01047E10 6E135A60,6E15DB00,RegCloseKey,6E135A60,NtSetValueKey,RegCloseKey, | 12_2_01047E10 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01044D70 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,ReadProcessMemory,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle, | 12_2_01044D70 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010554DC NtdllDefWindowProc_A,NtdllDefWindowProc_A, | 12_2_010554DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01047D48 6E135A60,NtDeleteValueKey,RegCloseKey, | 12_2_01047D48 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010458B8 CreateEventA,GetCurrentProcessId,CreateProcessW,Sleep,NtCreateSection,NtCreateSection,NtUnmapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,ResumeThread,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,TerminateProcess,CloseHandle,CloseHandle,6E15D4C0, | 12_2_010458B8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010440E8 OpenProcess,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,GetCurrentProcess,NtMapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,GetCurrentProcess,NtUnmapViewOfSection,CloseHandle,CloseHandle,CloseHandle, | 12_2_010440E8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010123CC NtQueryInformationProcess, | 12_2_010123CC |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wow64log.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: wow64log.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Section loaded: phoneinfo.dll |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Section loaded: wow64log.dll |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wow64log.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: wow64log.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: sfc.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: vboxhook.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: phoneinfo.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: wow64log.dll |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: sfc.dll |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02584F79 __EH_prolog,SetErrorMode,SetUnhandledExceptionFilter,GetSystemDefaultLangID,GetUserDefaultLangID,GetUserDefaultUILanguage,Sleep,CopyFileW,DeleteFileW,CreateThread,CloseHandle,GetLastError,RegOpenKeyExA,WaitForSingleObject,RegDeleteValueA,RegCloseKey, | 3_2_02584F79 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_0258D598 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 3_2_0258D598 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02584F79 __EH_prolog,SetErrorMode,SetUnhandledExceptionFilter,GetSystemDefaultLangID,GetUserDefaultLangID,GetUserDefaultUILanguage,Sleep,CopyFileW,DeleteFileW,CreateThread,CloseHandle,GetLastError,RegOpenKeyExA,WaitForSingleObject,RegDeleteValueA,RegCloseKey, | 3_2_02584F79 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_0258EF7A SetUnhandledExceptionFilter, | 3_2_0258EF7A |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02584F79 __EH_prolog,SetErrorMode,SetUnhandledExceptionFilter,GetSystemDefaultLangID,GetUserDefaultLangID,GetUserDefaultUILanguage,Sleep,CopyFileW,DeleteFileW,CreateThread,CloseHandle,GetLastError,RegOpenKeyExA,WaitForSingleObject,RegDeleteValueA,RegCloseKey, | 3_2_02584F79 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025901E2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 3_2_025901E2 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_00406B46 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 3_1_00406B46 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_004071D4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 3_1_004071D4 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_00413C1F SetUnhandledExceptionFilter,UnhandledExceptionFilter,RtlUnwind, | 3_1_00413C1F |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_0040DC7C SetUnhandledExceptionFilter, | 3_1_0040DC7C |
Source: C:\Windows\System32\conhost.exe | Code function: 8_2_00007FF6C8BE1C7C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 8_2_00007FF6C8BE1C7C |
Source: C:\Windows\System32\conhost.exe | Code function: 8_2_00007FF6C8BE19A0 SetUnhandledExceptionFilter, | 8_2_00007FF6C8BE19A0 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_025897BF __EH_prolog,FindFirstFileW,__wcsicoll,__wcsicoll,FindNextFileW,FindClose, | 3_2_025897BF |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_2_02587314 FindFirstFileW,FindClose, | 3_2_02587314 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: 3_1_0040200D CryptMsgCountersignEncoded,LoadMenuA,CreateMenu,LoadMenuA,LoadBitmapA,AppendMenuA,LoadMenuA,CryptMsgDuplicate,GetStockObject,GetStockObject,SelectObject,GetStockObject,GetObjectA,SendMessageA,OffsetRect,GetPixel,BeginPaint,DrawTextA,DefWindowProcA,BeginPaint,GetClientRect,DrawTextA,EndPaint,PostQuitMessage,DefWindowProcA,GetDlgItem,CreateWindowExA,BeginPaint,SetWindowPos,SetWindowLongA,BeginPaint,MultiByteToWideChar,BeginPaint,MultiByteToWideChar,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,GetWindowRect,GetCursorPos,PtInRect,SendMessageA,GetScrollPos,SetScrollPos,InvalidateRect,BeginPaint,LockResource,GetClientRect,DrawTextA,EndPaint,MoveWindow,SetFocus,FreeResource,PostQuitMessage,GetDC,GetTextMetricsA,ReleaseDC,GetSystemMetrics,CreateWindowExA,LoadStringA,FindResourceA,LoadResource,LockResource,CharNextA,SetScrollRange,SetScrollPos,SendMessageA,GetLastError,CreateWindowExA,ImageList_Create,SendMessageA,SendMessageA,ICLocate,ICOpen,ICSendMessage,ICClose,ICInfo,ICGetInfo,SendM | 3_1_0040200D |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B29E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B29E80 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00AE5840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 5_2_00AE5840 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 5_2_00B2B32C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 5_2_00B2B08C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B163DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B163DC |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: 5_2_00B2B420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 5_2_00B2B420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 9_2_008CB32C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_00885840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 9_2_00885840 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008D1E74 FindFirstFileW,6E15D4C0,6E15DFB0,6E15D4C0,FindNextFileW,FindClose,FindFirstFileW,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW,FindNextFileW,FindClose,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW, | 9_2_008D1E74 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008CB420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008CB08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 9_2_008CB08C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008B63DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008B63DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 9_2_008C9E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 9_2_008C9E80 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B32C FindFirstFileW,FindClose,FileTimeToSystemTime, | 12_2_0104B32C |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_010363DC FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_010363DC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01005840 GetModuleHandleA,GetProcAddress,lstrcpy,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpy,lstrlen,lstrcpy, | 12_2_01005840 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B420 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_0104B420 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01051E74 FindFirstFileW,6E15D4C0,6E15DFB0,6E15D4C0,FindNextFileW,FindClose,FindFirstFileW,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW,FindNextFileW,FindClose,RemoveDirectoryW,6E15DFB0,RemoveDirectoryW, | 12_2_01051E74 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_01049E80 FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime,FindFirstFileW,FindClose,FileTimeToSystemTime,FileTimeToSystemTime, | 12_2_01049E80 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: 12_2_0104B08C FindFirstFileW,FindClose,FileTimeToSystemTime, | 12_2_0104B08C |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 916 | Thread sleep count: 512 > 30 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 916 | Thread sleep time: -25600s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 2812 | Thread sleep count: 110 > 30 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 2812 | Thread sleep time: -110000s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 3068 | Thread sleep time: -5000s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 2840 | Thread sleep time: -500s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 2812 | Thread sleep time: -3000s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe TID: 2776 | Thread sleep time: -99999999s >= -60s |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 752 | Thread sleep count: 549 > 30 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 752 | Thread sleep count: 43 > 30 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1844 | Thread sleep time: -1000s >= -60s |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2764 | Thread sleep time: -99999999s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3268 | Thread sleep count: 905 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3268 | Thread sleep time: -45250s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3296 | Thread sleep count: 317 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3296 | Thread sleep time: -317000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 1780 | Thread sleep time: -1500s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3284 | Thread sleep count: 502 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3284 | Thread sleep time: -50200s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3284 | Thread sleep count: 111 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3284 | Thread sleep time: -55500s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3288 | Thread sleep time: -3000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3272 | Thread sleep count: 36 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3272 | Thread sleep time: -180000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3012 | Thread sleep time: -60000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 1780 | Thread sleep time: -15000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 1912 | Thread sleep time: -5000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3432 | Thread sleep time: -120000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 2952 | Thread sleep time: -99999999s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3316 | Thread sleep count: 885 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3316 | Thread sleep time: -44250s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3340 | Thread sleep count: 111 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3340 | Thread sleep time: -55500s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3332 | Thread sleep count: 163 > 30 |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3332 | Thread sleep time: -163000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3352 | Thread sleep time: -5000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 3352 | Thread sleep time: -1000s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 780 | Thread sleep time: -99999999s >= -60s |
Source: C:\Windows\SysWOW64\regsvr32.exe TID: 2828 | Thread sleep time: -99999999s >= -60s |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: GetUserDefaultUILanguage,GetLocaleInfoA, | 3_2_02587505 |
Source: C:\Users\admin\AppData\Local\Temp\a1.exe | Code function: GetLocaleInfoA, | 3_1_00412110 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 5_2_00AE59E8 |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 5_2_00AE5ABB |
Source: C:\Users\admin\AppData\Local\Temp\a2.exe | Code function: GetLocaleInfoA,GetLocaleInfoA, | 5_2_00B2D8FC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: GetModuleFileNameA,6E15DCD0,6E15DCD0,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 9_2_008859E8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: GetLocaleInfoA,GetLocaleInfoA, | 9_2_008CD8FC |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 9_2_00885ABB |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: GetModuleFileNameA,6E15DCD0,6E15DCD0,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 12_2_010059E8 |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, | 12_2_01005ABB |
Source: C:\Windows\SysWOW64\regsvr32.exe | Code function: GetLocaleInfoA,GetLocaleInfoA, | 12_2_0104D8FC |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Diagnostics.Tracing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Diagnostics.Tracing.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.10586.0.cat VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.10586.0.cat VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.10586.0.cat VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.10586.0.cat VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.10586.0.cat VolumeInformation |