Source: global traffic | HTTP traffic detected: POST /index.html HTTP/1.1Connection: Keep-AliveContent-Type: application/octet-streamAccept: */*User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36Content-Length: 440Host: 192.243.101.124 |
Source: global traffic | HTTP traffic detected: POST /index.html HTTP/1.1Connection: Keep-AliveContent-Type: application/octet-streamAccept: */*User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36Content-Length: 32Host: 192.243.101.124 |
Source: explorer.exe | String found in binary or memory: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/ASC.exellQ |
Source: explorer.exe | String found in binary or memory: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/ASC.exewlP |
Source: explorer.exe | String found in binary or memory: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/ASC.exeznX |
Source: govrat.exe | String found in binary or memory: http://%S |
Source: govrat.exe | String found in binary or memory: http://192.243.101.124/index.html |
Source: govrat.exe | String found in binary or memory: http://192.243.101.124/index.htmlZZ) |
Source: govrat.exe | String found in binary or memory: http://192.243.101.124e: |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0 |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: http://t2.symcb.com0 |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: http://tl.symcb.com/tl.crl0 |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: http://tl.symcb.com/tl.crt0 |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: http://tl.symcd.com0& |
Source: explorer.exe | String found in binary or memory: http://www.%s.comPA |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: https://www.thawte.com/cps0/ |
Source: govrat.exe, ASC.exe.1.dr | String found in binary or memory: https://www.thawte.com/repository0W |
Source: govrat.exe | Static PE information: Section: .vmp1 IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: ASC.exe.1.dr | Static PE information: Section: .vmp1 IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: govrat.exe | Static PE information: section name: .vmp0 |
Source: govrat.exe | Static PE information: section name: .vmp1 |
Source: ASC.exe.1.dr | Static PE information: section name: .vmp0 |
Source: ASC.exe.1.dr | Static PE information: section name: .vmp1 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098C272 push edi; ret | 1_2_00A13AA9 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009793A1 push edi; ret | 1_2_009793AD |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097B969 push edi; ret | 1_2_0097B96A |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00985056 push edi; ret | 1_2_009D5A71 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098B0D1 push edi; ret | 1_2_009D404F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00988D9E push edi; ret | 1_2_00988D9F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097D79A push edi; ret | 1_2_00A168D4 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097D711 push edi; ret | 1_2_00A0B8EA |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009805CE push edi; ret | 1_2_009805E4 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009802DE push edi; ret | 1_2_009A0EEB |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00977DA3 push edi; ret | 1_2_009CDFD4 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009852AF push edi; ret | 1_2_009852B0 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009814F4 push edi; ret | 1_2_009DBD75 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097B278 push edi; ret | 1_2_009B9A2F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009580A5 push ecx; ret | 1_2_009580B8 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098B5E4 push edi; ret | 1_2_009BF3FE |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097A9B7 push edi; ret | 1_2_0097A9B8 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097AC17 push edi; ret | 1_2_009B4D65 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098AE5D push edi; ret | 1_2_009DAA7F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097E453 push edi; ret | 1_2_009BD6B9 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097FD03 push edi; ret | 1_2_0097FD04 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00978BE0 push edi; ret | 1_2_009B02B9 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00985D50 push edi; ret | 1_2_00985D6B |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00984432 push edi; ret | 1_2_009C3C86 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00979733 push edi; ret | 1_2_009AF6C2 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098360A push edi; ret | 1_2_009F21C4 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0098C32A push edi; ret | 1_2_009F7EA7 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097808D push edi; ret | 1_2_009EA573 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097C3A0 push edi; ret | 1_2_0097C3A1 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0097A11B push edi; ret | 1_2_0097A11C |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00986FCD push edi; ret | 1_2_00986FCE |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00960762 GetProcAddress,GetProcAddress,FindFirstFileA,GetProcAddress, | 1_2_00960762 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D0762 GetProcAddress,GetProcAddress,FindFirstFileA,GetProcAddress, | 5_2_012D0762 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0095FE2E GetProcAddress,GetProcAddress,GetProcAddress,K32EnumDeviceDrivers,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,__wcsicoll, | 1_2_0095FE2E |
Source: C:\Users\user\Desktop\govrat.exe | Memory allocated: 772C0000 page execute and read and write | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Memory allocated: 771C0000 page execute and read and write | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Memory allocated: 772C0000 page execute and read and write | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Memory allocated: 771C0000 page execute and read and write | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Memory allocated: 772C0000 page execute and read and write | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Memory allocated: 771C0000 page execute and read and write | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_009641C3 | 1_2_009641C3 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00966000 | 1_2_00966000 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00956502 | 1_2_00956502 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0095FB7F | 1_2_0095FB7F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0096A780 | 1_2_0096A780 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0096AE5C | 1_2_0096AE5C |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00966EED | 1_2_00966EED |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0096A22F | 1_2_0096A22F |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_0096BB94 | 1_2_0096BB94 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00969CDE | 1_2_00969CDE |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00967EA6 | 1_2_00967EA6 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_1_00AC01CE | 1_1_00AC01CE |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_1_00ABFE67 | 1_1_00ABFE67 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012DBB94 | 5_2_012DBB94 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D41C3 | 5_2_012D41C3 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D7EA6 | 5_2_012D7EA6 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012DA780 | 5_2_012DA780 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D9CDE | 5_2_012D9CDE |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D6000 | 5_2_012D6000 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012C6502 | 5_2_012C6502 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012CFB7F | 5_2_012CFB7F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012DA22F | 5_2_012DA22F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012DAE5C | 5_2_012DAE5C |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D6EED | 5_2_012D6EED |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_1_014301CE | 5_1_014301CE |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_1_0142FE67 | 5_1_0142FE67 |
Source: govrat.exe | Binary or memory string: OriginalFilenamewow64.dllj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewow64lg2.dllj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewow64cpu.dllj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameKernelbasej% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameCSRSS.Exe.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewinsrv.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWinInit.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWINLOGON.EXE.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameuser32j% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameservices.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamelsasrv.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamesvchost.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSETUPAPI.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewshtcpip.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewship6.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewshqos.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameAUTHUI.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametzres.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamesppsvc.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameInput.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameTipTsf.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSpTip.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameTableTextService.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamegpsvc.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameaero.msstyles.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametaskcomp.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameCRYPT32.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamespoolsv.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameBFE.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameFirewallAPI.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametaskhost.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameUSERINIT.EXE.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: originalfilename vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameEXPLORER.EXE.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameMSCMS.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamej% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameMsCtfMonitor.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamesnmptrap.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamelmhsvc.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamedwm.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamedhcpcore.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamepeerdistsh.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameNetLogon.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamesstpsvc.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamelocalspl.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamenetmsg.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSHELL32.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameFXSRESM.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametaskeng.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWsdMon.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamevsstrace.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWLDAP32.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamenetprofm.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameThemeUI.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameExplorerFrame.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameesrb.dll.muiH vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamexpsrchvw.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamestobject.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamerasdlg.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameAltTab.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewscui.cpl.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameHCPROVIDERS.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSearchIndexer.exe.mui@ vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamePNIDUI.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametquery.dll.mui@ vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamesidebar.EXE.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameMsMpRes.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametwext.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamempr.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameschedsvc.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameFDResPub.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameFunDisc.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamerpcrt4.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameFDPrint.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameBASEBRD.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameimageres.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWINMM.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameDocumentPerformanceEvents.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameWerConCpl.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameMSHTML.DLL.MUID vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSHSVCS.DLL.MUIj% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenametaskmgr.exe.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameSndVolSSO.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenamewin32spl.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameinetpp.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameadvapi32.dll.muij% vs govrat.exe |
Source: govrat.exe | Binary or memory string: OriginalFilenameprovsvc.dll.muij% vs govrat.exe |
Source: C:\Users\user\Desktop\govrat.exe | String freed: SELECT * FROM Win32_Processor | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | String freed: SELECT * FROM Win32_Processor | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | String freed: SELECT * FROM Win32_Processor | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | String freed: SELECT * FROM Win32_Processor | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor | |
Source: unknown | Process created: C:\Users\user\Desktop\govrat.exe 'C:\Users\user\Desktop\govrat.exe' | |
Source: unknown | Process created: C:\Windows\SysWOW64\explorer.exe explorer.exe C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | |
Source: unknown | Process created: C:\Windows\explorer.exe C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe 'C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe' | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe 'C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe' | Jump to behavior |
Source: | Binary string: wow64win.pdb source: govrat.exe, explorer.exe, ASC.exe |
Source: | Binary string: wow64cpu.pdb source: govrat.exe, explorer.exe, ASC.exe |
Source: | Binary string: wow64.pdbH source: govrat.exe, explorer.exe, ASC.exe |
Source: | Binary string: wow64win.pdbH source: govrat.exe, explorer.exe, ASC.exe |
Source: | Binary string: wow64.pdb source: govrat.exe, explorer.exe, ASC.exe |
Source: C:\Users\user\Desktop\govrat.exe | Code function: GetProcAddress,GetProcAddress,GetProcAddress,K32EnumDeviceDrivers,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,__wcsicoll, | 1_2_0095FE2E |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: GetProcAddress,GetProcAddress,GetProcAddress,K32EnumDeviceDrivers,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,__wcsicoll, | 5_2_012CFE2E |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00960762 GetProcAddress,GetProcAddress,FindFirstFileA,GetProcAddress, | 1_2_00960762 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Code function: 5_2_012D0762 GetProcAddress,GetProcAddress,FindFirstFileA,GetProcAddress, | 5_2_012D0762 |
Source: C:\Users\user\Desktop\govrat.exe | Code function: 1_2_00965B62 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, | 1_2_00965B62 |
Source: C:\Users\user\Desktop\govrat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\govrat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ASC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |