Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475507 CryptAcquireContextW,CryptAcquireContextW,GetLastError,CryptAcquireContextW, | 3_2_00475507 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475BC4 GetSystemInfo,__alldiv,MapViewOfFile,CryptDuplicateHash,CryptHashData,LocalAlloc,CryptGetHashParam,memcpy,FlushViewOfFile,LocalFree,CryptDestroyHash,UnmapViewOfFile, | 3_2_00475BC4 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_004715A7 GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,HeapAlloc,CryptAcquireContextW,GetProcessHeap,HeapAlloc,CryptImportKey,CryptCreateHash,CryptSetHashParam,GetProcessHeap,HeapFree,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptDestroyKey,CryptReleaseContext, | 3_2_004715A7 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475A73 GetSystemInfo,__alldiv,MapViewOfFile,CryptDuplicateHash,CryptHashData,LocalAlloc,CryptGetHashParam,LocalFree,CryptDestroyHash,UnmapViewOfFile, | 3_2_00475A73 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475613 CryptStringToBinaryW,CryptStringToBinaryW,LocalAlloc,LocalAlloc,CryptStringToBinaryW,CryptDecodeObjectEx,CryptDecodeObjectEx,LocalAlloc,CryptDecodeObjectEx,CryptImportPublicKeyInfo,LocalFree,LocalFree, | 3_2_00475613 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475D0A CryptDuplicateKey,CreateFileW,GetFileSizeEx,__alldiv,CreateFileMappingW,MapViewOfFile,CryptEncrypt,FlushViewOfFile,UnmapViewOfFile,CloseHandle,CloseHandle,CryptDestroyKey,SetEvent, | 3_2_00475D0A |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_0047554A CryptAcquireContextW,GetLastError,CryptGenRandom,CryptReleaseContext, | 3_2_0047554A |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00476299 CreateEventW,CreateThread,WaitForSingleObject,CloseHandle,CryptDestroyHash,CryptDestroyKey,CryptDestroyKey,CryptReleaseContext,CloseHandle,LocalFree, | 3_2_00476299 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_0047559B CryptSetKeyParam,CryptSetKeyParam,CryptSetKeyParam,CryptGetKeyParam,LocalAlloc,CryptSetKeyParam,LocalFree, | 3_2_0047559B |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00475780 CryptBinaryToStringW,CryptBinaryToStringW,LocalAlloc,CryptBinaryToStringW,LocalFree, | 3_2_00475780 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_004756D8 CryptEncrypt,CryptEncrypt,LocalAlloc,memcpy,CryptEncrypt,LocalFree, | 3_2_004756D8 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00476085 CryptCreateHash,CryptHashData,CryptDeriveKey,CryptDestroyHash, | 3_2_00476085 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00476246 CryptCreateHash,CryptHashData,CryptGetHashParam, | 3_2_00476246 |
Source: rundll32.exe | String found in binary or memory: http://192.168.1.2/ |
Source: rundll32.exe | String found in binary or memory: http://192.168.1.2/g |
Source: i0YxTJ2SO.exe, cscc.dat.3.dr, infpub.dat.1.dr | String found in binary or memory: http://crl.thawte.com/thawtetimestampingca.crl0 |
Source: rundll32.exe, cscc.dat.3.dr, dispci.exe.3.dr | String found in binary or memory: http://diskcryptor.net/ |
Source: i0YxTJ2SO.exe, cscc.dat.3.dr, infpub.dat.1.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://rb.symcb.com/rb.crl0w |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://rb.symcb.com/rb.crt0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://rb.symcd.com0& |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://s.symcb.com/universal-root.crl0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://s.symcd.com0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://s.symcd.com06 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://sf.symcb.com/sf.crl0w |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://sf.symcb.com/sf.crt0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://sf.symcd.com0& |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( |
Source: i0YxTJ2SO.exe, cscc.dat.3.dr, infpub.dat.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 |
Source: i0YxTJ2SO.exe, cscc.dat.3.dr, infpub.dat.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: i0YxTJ2SO.exe, cscc.dat.3.dr, infpub.dat.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com0; |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: infpub.dat.1.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: https://d.symcb.com/rpa0. |
Source: i0YxTJ2SO.exe, infpub.dat.1.dr | String found in binary or memory: https://d.symcb.com/rpa06 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ProgID |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_USERS\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\schtasks.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00479534 wsprintfW,wsprintfW,wsprintfW,wsprintfW,PathFindExtensionW,wsprintfW,GetLastError,WNetAddConnection2W,PathFileExistsW,GetLastError,GetLastError,WNetCancelConnection2W,OpenSCManagerW,memset,GetSystemTimeAsFileTime,wsprintfW,CreateServiceW,StartServiceW,GetLastError,QueryServiceStatus,Sleep,DeleteService,CloseServiceHandle,GetLastError,CloseServiceHandle,GetLastError,DeleteFileW,WNetCancelConnection2W,SetLastError, \\%s\admin$ | 3_2_00479534 |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00479B63 wsprintfW,wsprintfW,wsprintfW,wsprintfW,PathFindExtensionW,wsprintfW,WNetAddConnection2W,PathFileExistsW,GetLastError,GetLastError,WNetCancelConnection2W,GetCurrentThread,OpenThreadToken,DuplicateTokenEx,memset,GetSystemDirectoryW,CloseHandle,PathAppendW,PathFileExistsW,wsprintfW,CreateProcessAsUserW,CreateProcessW,WaitForSingleObject,GetExitCodeProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,PathFileExistsW,GetLastError,GetLastError,DeleteFileW,CloseHandle,CloseHandle,WNetCancelConnection2W,SetLastError, \\%s\admin$ | 3_2_00479B63 |
Source: C:\Windows\System32\rundll32.exe | Code function: OpenSCManagerW,GetLastError,CreateServiceW,GetLastError,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle, | 3_2_00471368 |
Source: C:\Windows\System32\rundll32.exe | Code function: wsprintfW,wsprintfW,wsprintfW,wsprintfW,PathFindExtensionW,wsprintfW,GetLastError,WNetAddConnection2W,PathFileExistsW,GetLastError,GetLastError,WNetCancelConnection2W,OpenSCManagerW,memset,GetSystemTimeAsFileTime,wsprintfW,CreateServiceW,StartServiceW,GetLastError,QueryServiceStatus,Sleep,DeleteService,CloseServiceHandle,GetLastError,CloseServiceHandle,GetLastError,DeleteFileW,WNetCancelConnection2W,SetLastError, | 3_2_00479534 |
Source: unknown | Process created: C:\Users\user\Desktop\i0YxTJ2SO.exe 'C:\Users\user\Desktop\i0YxTJ2SO.exe' |
Source: unknown | Process created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\infpub.dat,#1 15 |
Source: unknown | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN rhaegal |
Source: unknown | Process created: C:\Windows\System32\schtasks.exe schtasks /Delete /F /TN rhaegal |
Source: unknown | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: unknown | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: unknown | Process created: C:\Windows\9706.tmp 'C:\Windows\9706.tmp' \\.\pipe\{EE91B260-F47B-4E8B-B208-21BD25A3C0CE} |
Source: unknown | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: unknown | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: unknown | Process created: C:\Windows\System32\cmd.exe /c wevtutil cl Setup & wevtutil cl System & wevtutil cl Security & wevtutil cl Application & fsutil usn deletejournal /D C: |
Source: unknown | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Setup |
Source: unknown | Process created: C:\Windows\System32\shutdown.exe C:\Windows\system32\shutdown.exe /r /t 0 /f |
Source: unknown | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl System |
Source: unknown | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Security |
Source: unknown | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN drogon |
Source: unknown | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Application |
Source: unknown | Process created: C:\Windows\System32\LogonUI.exe 'LogonUI.exe' /flags:0x0 |
Source: unknown | Process created: C:\Windows\System32\schtasks.exe unknown |
Source: unknown | Process created: C:\Windows\System32\fsutil.exe unknown |
Source: C:\Users\user\Desktop\i0YxTJ2SO.exe | Process created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\infpub.dat,#1 15 |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN rhaegal |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\9706.tmp 'C:\Windows\9706.tmp' \\.\pipe\{EE91B260-F47B-4E8B-B208-21BD25A3C0CE} |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c wevtutil cl Setup & wevtutil cl System & wevtutil cl Security & wevtutil cl Application & fsutil usn deletejournal /D C: |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN drogon |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Delete /F /TN rhaegal |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Setup |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl System |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Security |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Application |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe unknown |
Source: C:\Windows\System32\rundll32.exe | Code function: 3_2_00479B63 wsprintfW,wsprintfW,wsprintfW,wsprintfW,PathFindExtensionW,wsprintfW,WNetAddConnection2W,PathFileExistsW,GetLastError,GetLastError,WNetCancelConnection2W,GetCurrentThread,OpenThreadToken,DuplicateTokenEx,memset,GetSystemDirectoryW,CloseHandle,PathAppendW,PathFileExistsW,wsprintfW,CreateProcessAsUserW,CreateProcessW,WaitForSingleObject,GetExitCodeProcess,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,PathFileExistsW,GetLastError,GetLastError,DeleteFileW,CloseHandle,CloseHandle,WNetCancelConnection2W,SetLastError, | 3_2_00479B63 |
Source: C:\Users\user\Desktop\i0YxTJ2SO.exe | Process created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\infpub.dat,#1 15 |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN rhaegal |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\9706.tmp 'C:\Windows\9706.tmp' \\.\pipe\{EE91B260-F47B-4E8B-B208-21BD25A3C0CE} |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c wevtutil cl Setup & wevtutil cl System & wevtutil cl Security & wevtutil cl Application & fsutil usn deletejournal /D C: |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\System32\cmd.exe /c schtasks /Delete /F /TN drogon |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Delete /F /TN rhaegal |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR 'C:\Windows\system32\cmd.exe /C Start \'\' \'C:\Windows\dispci.exe\' -id 3818518496 && exit' |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 10:36:00 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Setup |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl System |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Security |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil cl Application |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe unknown |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 2000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 500 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 1000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 300000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 900000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 180000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 3000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 10000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 180000 |
Source: C:\Windows\System32\rundll32.exe | Thread delayed: delay time: 500 |
Source: C:\Windows\System32\rundll32.exe TID: 3468 | Thread sleep time: -2000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3540 | Thread sleep time: -5000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3548 | Thread sleep time: -1000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3628 | Thread sleep time: -300000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3468 | Thread sleep time: -900000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3544 | Thread sleep time: -540000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3468 | Thread sleep time: -3000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3624 | Thread sleep time: -10000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3544 | Thread sleep time: -180000s >= -60s |
Source: C:\Windows\System32\rundll32.exe TID: 3540 | Thread sleep time: -500s >= -60s |
Source: C:\Windows\System32\LogonUI.exe TID: 3960 | Thread sleep time: -60000s >= -60s |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX |