Loading ...

Play interactive tourEdit tour

Analysis Report starx.exe

Overview

General Information

Sample Name:starx.exe
Analysis ID:286806
MD5:2689e0bd727c85849f786822b360cd28
SHA1:ae242d8709f588cc91f9ab814a5efeb6c1a160bc
SHA256:37a4202e64f88ef928f46cdb05653527a1201aaffd431022eececff19348515b

Most interesting Screenshot:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected AgentTesla
Contains functionality to detect sleep reduction / modifications
Found evasive API chain (may execute only at specific dates)
Machine Learning detection for sample
Maps a DLL or memory area into another process
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file access)
Antivirus or Machine Learning detection for unpacked file
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to detect sandboxes (mouse cursor move detection)
Contains functionality to detect virtual machines (SLDT)
Contains functionality to dynamically determine API calls
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain (date check)
Found evasive API chain (may stop execution after checking a module file name)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May check if the current machine is a sandbox (GetTickCount - Sleep)
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)
Yara detected Credential Stealer

Classification

Startup

  • System is w10x64
  • starx.exe (PID: 6728 cmdline: 'C:\Users\user\Desktop\starx.exe' MD5: 2689E0BD727C85849F786822B360CD28)
    • starx.exe (PID: 6960 cmdline: 'C:\Users\user\Desktop\starx.exe' MD5: 2689E0BD727C85849F786822B360CD28)
  • cleanup

Malware Configuration

Threatname: Agenttesla

{"Username: ": "KUwgxo", "URL: ": "http://PsF9BDspIqQdTVi.net", "To: ": "szoro0@yandex.com", "ByHost: ": "smtp.yandex.com:587", "Password: ": "SzYscCJ", "From: ": "szoro0@yandex.com"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000002.00000002.1009380756.000000000044B000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    00000000.00000002.365000476.00000000041BB000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
      00000002.00000002.1009882459.0000000000630000.00000004.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
        00000002.00000002.1010610583.0000000000AF2000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000002.00000002.1009281768.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
            Click to see the 8 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            2.2.starx.exe.630000.2.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
              2.2.starx.exe.af0000.5.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                2.2.starx.exe.630000.2.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  2.2.starx.exe.400000.0.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                    2.2.starx.exe.ab0000.4.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                      Click to see the 1 entries

                      Sigma Overview

                      No Sigma rule has matched

                      Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Antivirus / Scanner detection for submitted sampleShow sources
                      Source: starx.exeAvira: detected
                      Found malware configurationShow sources
                      Source: starx.exe.6960.2.memstrMalware Configuration Extractor: Agenttesla {"Username: ": "KUwgxo", "URL: ": "http://PsF9BDspIqQdTVi.net", "To: ": "szoro0@yandex.com", "ByHost: ": "smtp.yandex.com:587", "Password: ": "SzYscCJ", "From: ": "szoro0@yandex.com"}
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: starx.exeVirustotal: Detection: 57%Perma Link
                      Source: starx.exeMetadefender: Detection: 34%Perma Link
                      Source: starx.exeReversingLabs: Detection: 82%
                      Machine Learning detection for sampleShow sources
                      Source: starx.exeJoe Sandbox ML: detected
                      Source: 2.2.starx.exe.af0000.5.unpackAvira: Label: TR/Spy.Gen8
                      Source: 0.2.starx.exe.25b0000.3.unpackAvira: Label: TR/Patched.Ren.Gen
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00408454 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime,0_2_00408454
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00405098 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn,0_2_00405098
                      Source: global trafficTCP traffic: 192.168.2.3:49761 -> 77.88.21.158:587
                      Source: Joe Sandbox ViewIP Address: 77.88.21.158 77.88.21.158
                      Source: global trafficTCP traffic: 192.168.2.3:49761 -> 77.88.21.158:587
                      Source: unknownDNS traffic detected: queries for: smtp.yandex.com
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: http://DynDns.comDynDNS
                      Source: starx.exe, 00000002.00000002.1014070589.0000000002A0E000.00000004.00000001.sdmp, starx.exe, 00000002.00000002.1014591376.0000000002ABE000.00000004.00000001.sdmp, starx.exe, 00000002.00000003.556314586.0000000005241000.00000004.00000001.sdmpString found in binary or memory: http://PsF9BDspIqQdTVi.net
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://crl.certum.pl/ca.crl0h
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://crl.certum.pl/ctnca.crl0k
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://crls.yandex.net/certum/ycasha2.crl0-
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://repository.certum.pl/ca.cer09
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://repository.certum.pl/ctnca.cer09
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://repository.certum.pl/ycasha2.cer0
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: http://rvlyyV.com
                      Source: starx.exe, 00000002.00000002.1014427219.0000000002A8C000.00000004.00000001.sdmpString found in binary or memory: http://smtp.yandex.com
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://subca.ocsp-certum.com0.
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://subca.ocsp-certum.com01
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://www.certum.pl/CPS0
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://yandex.crl.certum.pl/ycasha2.crl0q
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: http://yandex.ocsp-responder.com03
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: https://api.ipify.orgGETMozilla/5.0
                      Source: starx.exe, 00000000.00000002.365000476.00000000041BB000.00000040.00000001.sdmp, starx.exe, 00000002.00000002.1009380756.000000000044B000.00000040.00000001.sdmpString found in binary or memory: https://api.telegram.org/bot%telegramapi%/
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: https://api.telegram.org/bot%telegramapi%/sendDocumentdocument---------------------------x
                      Source: starx.exe, 00000002.00000002.1014474484.0000000002A99000.00000004.00000001.sdmpString found in binary or memory: https://www.certum.pl/CPS0
                      Source: starx.exeString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
                      Source: starx.exe, 00000002.00000002.1013605272.0000000002981000.00000004.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00420CC0 GetClipboardData,CopyEnhMetaFileA,GetEnhMetaFileHeader,0_2_00420CC0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0043DD3C GetKeyboardState,0_2_0043DD3C
                      Source: starx.exe, 00000000.00000002.361495785.00000000007DA000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00440CB8 NtdllDefWindowProc_A,GetCapture,0_2_00440CB8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045BA98 NtdllDefWindowProc_A,0_2_0045BA98
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045C240 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A,0_2_0045C240
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045C2F0 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus,0_2_0045C2F0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042A524 NtdllDefWindowProc_A,0_2_0042A524
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00450C40 GetSubMenu,SaveDC,RestoreDC,739EB080,SaveDC,RestoreDC,NtdllDefWindowProc_A,0_2_00450C40
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_00444159 NtCreateSection,2_2_00444159
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00450C400_2_00450C40
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00455F900_2_00455F90
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_004022962_2_00402296
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_0043D9762_2_0043D976
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_0044313D2_2_0044313D
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024C46A02_2_024C46A0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024C35C42_2_024C35C4
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024C45B02_2_024C45B0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024C53702_2_024C5370
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024C35B82_2_024C35B8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_024CDA002_2_024CDA00
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_059D75402_2_059D7540
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_059D94F82_2_059D94F8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_059D6C702_2_059D6C70
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_059D69282_2_059D6928
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_059D25482_2_059D2548
                      Source: C:\Users\user\Desktop\starx.exeCode function: String function: 00403FC0 appears 68 times
                      Source: C:\Users\user\Desktop\starx.exeCode function: String function: 004060D4 appears 62 times
                      Source: starx.exeStatic PE information: Resource name: RT_BITMAP type: GLS_BINARY_LSB_FIRST
                      Source: starx.exeStatic PE information: Resource name: RT_BITMAP type: GLS_BINARY_LSB_FIRST
                      Source: starx.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: starx.exe, 00000000.00000002.365112708.00000000041F2000.00000040.00000001.sdmpBinary or memory string: OriginalFilenameNDEDCeTcqHyGOpNvotAEY.exe4 vs starx.exe
                      Source: starx.exe, 00000000.00000002.361463897.0000000000780000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs starx.exe
                      Source: starx.exe, 00000000.00000002.361470848.0000000000790000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameCOMCTL32.DLL.MUIj% vs starx.exe
                      Source: starx.exeBinary or memory string: OriginalFilename vs starx.exe
                      Source: starx.exe, 00000002.00000002.1009380756.000000000044B000.00000040.00000001.sdmpBinary or memory string: OriginalFilenameNDEDCeTcqHyGOpNvotAEY.exe4 vs starx.exe
                      Source: starx.exe, 00000002.00000002.1015558203.0000000005340000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameKernelbase.dll.muij% vs starx.exe
                      Source: starx.exe, 00000002.00000002.1009108498.0000000000197000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs starx.exe
                      Source: starx.exe, 00000002.00000002.1010502609.00000000008B0000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameCRYPT32.DLL.MUIj% vs starx.exe
                      Source: starx.exe, 00000002.00000002.1015457878.0000000005180000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamewbemdisp.tlbj% vs starx.exe
                      Source: starx.exe, 00000002.00000002.1010238341.00000000007B7000.00000004.00000020.sdmpBinary or memory string: OriginalFilenameclr.dllT vs starx.exe
                      Source: C:\Users\user\Desktop\starx.exeSection loaded: mscorwks.dllJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeSection loaded: mscorsec.dllJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeSection loaded: mscorjit.dllJump to behavior
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/0@2/1
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041DDA8 GetLastError,FormatMessageA,0_2_0041DDA8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00408606 GetDiskFreeSpaceA,0_2_00408606
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004137F4 FindResourceA,0_2_004137F4
                      Source: C:\Users\user\Desktop\starx.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\Desktop\starx.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\starx.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: starx.exeVirustotal: Detection: 57%
                      Source: starx.exeMetadefender: Detection: 34%
                      Source: starx.exeReversingLabs: Detection: 82%
                      Source: unknownProcess created: C:\Users\user\Desktop\starx.exe 'C:\Users\user\Desktop\starx.exe'
                      Source: unknownProcess created: C:\Users\user\Desktop\starx.exe 'C:\Users\user\Desktop\starx.exe'
                      Source: C:\Users\user\Desktop\starx.exeProcess created: C:\Users\user\Desktop\starx.exe 'C:\Users\user\Desktop\starx.exe' Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior

                      Data Obfuscation:

                      barindex
                      Detected unpacking (changes PE section rights)Show sources
                      Source: C:\Users\user\Desktop\starx.exeUnpacked PE file: 2.2.starx.exe.400000.0.unpack CODE:ER;DATA:W;BSS:W;.idata:W;.tls:W;.rdata:R;.reloc:R;.rsrc:R; vs .text:ER;.rsrc:R;.reloc:R;
                      Detected unpacking (overwrites its own PE header)Show sources
                      Source: C:\Users\user\Desktop\starx.exeUnpacked PE file: 2.2.starx.exe.400000.0.unpack
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004265C8 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_004265C8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004482AC push 00448339h; ret 0_2_00448331
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00416038 push ecx; mov dword ptr [esp], edx0_2_0041603A
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045E088 push 0045E0B4h; ret 0_2_0045E0AC
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00448244 push 004482AAh; ret 0_2_004482A2
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00426224 push 00426250h; ret 0_2_00426248
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004263D0 push 004263FCh; ret 0_2_004263F4
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00436418 push 00436444h; ret 0_2_0043643C
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00424540 push 0042456Ch; ret 0_2_00424564
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E57C push 0042E5A8h; ret 0_2_0042E5A0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E5CC push 0042E60Fh; ret 0_2_0042E607
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00436580 push 004365ACh; ret 0_2_004365A4
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00428608 push 00428661h; ret 0_2_00428659
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E634 push 0042E677h; ret 0_2_0042E66F
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004306C8 push 0043070Ah; ret 0_2_00430702
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004246D8 push 00424704h; ret 0_2_004246FC
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E6F0 push 0042E73Bh; ret 0_2_0042E733
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E698 push 0042E6E4h; ret 0_2_0042E6DC
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0042E748 push 0042E774h; ret 0_2_0042E76C
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00410736 push 004107AEh; ret 0_2_004107A6
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00410738 push 004107AEh; ret 0_2_004107A6
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004107B0 push 00410858h; ret 0_2_00410850
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041085A push 00410970h; ret 0_2_00410968
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041A8AE push 0041A95Bh; ret 0_2_0041A953
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041A8B0 push 0041A95Bh; ret 0_2_0041A953
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00410944 push 00410970h; ret 0_2_00410968
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041A960 push 0041A9F0h; ret 0_2_0041A9E8
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004069D4 push ecx; mov dword ptr [esp], eax0_2_004069D5
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0041A9F2 push 0041AD10h; ret 0_2_0041AD08
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00462A60 push 00462A8Ch; ret 0_2_00462A84
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00460AE4 push 00460B24h; ret 0_2_00460B1C
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00412ABC push ecx; mov dword ptr [esp], edx0_2_00412AC1
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045BB20 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus,0_2_0045BB20
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045C240 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A,0_2_0045C240
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_0045C2F0 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus,0_2_0045C2F0
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004423DC IsIconic,GetCapture,0_2_004423DC
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00424910 IsIconic,GetWindowPlacement,GetWindowRect,0_2_00424910
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00458B48 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow,0_2_00458B48
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_00442C90 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement,0_2_00442C90
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004435B4 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient,0_2_004435B4
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004265C8 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_004265C8
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\starx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion:

                      barindex
                      Contains functionality to detect sleep reduction / modificationsShow sources
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004371040_2_00437104
                      Found evasive API chain (may execute only at specific dates)Show sources
                      Source: C:\Users\user\Desktop\starx.exeEvasive API call chain: GetSystemTime,DecisionNodes,ExitProcessgraph_0-33587
                      Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)Show sources
                      Source: C:\Users\user\Desktop\starx.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)Show sources
                      Source: C:\Users\user\Desktop\starx.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                      Source: C:\Users\user\Desktop\starx.exeCode function: GetCurrentThreadId,GetCursorPos,WaitForSingleObject,0_2_0045B090
                      Source: C:\Users\user\Desktop\starx.exeCode function: 2_2_0040533C sldt word ptr [eax]2_2_0040533C
                      Source: C:\Users\user\Desktop\starx.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exeWindow / User API: threadDelayed 2002Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exeEvasive API call chain: GetSystemTime,DecisionNodesgraph_0-33587
                      Source: C:\Users\user\Desktop\starx.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleepgraph_2-40147
                      Source: C:\Users\user\Desktop\starx.exeAPI coverage: 7.1 %
                      Source: C:\Users\user\Desktop\starx.exeCode function: 0_2_004371040_2_00437104
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -922337203685477s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 4148Thread sleep count: 215 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -59782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 4148Thread sleep count: 2002 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -58908s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -117376s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -87423s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -57782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -56688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -84423s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -82782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -53188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -52782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -52282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -70032s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -46188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44876s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -67032s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -43782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -64782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -42688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -42282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -61782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -40782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -40282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -39688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -39188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -38782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -56532s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55923s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -72376s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -68376s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49923s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49032s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -47673s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -61376s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -30282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44673s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -57376s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -39423s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -37782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32532s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -119624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -89439s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -89109s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -59126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -176718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -58720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -234000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -58312s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -86439s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -143515s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -113812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -56720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -226000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -112624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -56126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -83718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -83439s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -166218s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -165000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -163500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -135780s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -134765s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -53626s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -106812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -185500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -105624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -78939s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -104624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -78189s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -129765s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -154500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -127500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -127030s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -75939s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -126015s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -50126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -74859s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -173250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -98624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73689s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73218s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -72939s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -121015s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -144000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -47720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -118750s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -94624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -47126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -93812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -46626s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -69609s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -46220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -184000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -68718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45626s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -67968s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -67689s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -112265s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -178000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -132000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -87624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -65439s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -130218s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -43126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -64359s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -42720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -170000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -105780s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -63189s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -62718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -62439s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -124218s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -41220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -40000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -57609s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -113718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -109218s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -88280s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -34906s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -34220s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -85000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33406s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -82265s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -63624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -31626s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -30720s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -76250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73515s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -56624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -81000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -64765s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -58750s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33609s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -31968s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -30609s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -38000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -30812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -88968s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -58000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -115624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -143500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -101250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -80624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -79812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -59109s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -136500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -77624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -57468s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -131250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -111000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -89765s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -106500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -69624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -86015s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -117250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -66624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32626s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -64812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -112000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -62624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -61812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -120000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -44718s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -72265s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -71250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55624s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -106000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -39468s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -63515s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -50000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36423s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -38188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36812s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33985s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -89391s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -143985s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -114000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -84141s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55906s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -54594s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -108188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -53688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -107000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -78891s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -52406s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -76641s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -101188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -50188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -75000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -49814s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73641s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48906s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -71391s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -94188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -69750s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -91188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45406s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -66141s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -87188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -64500s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -84188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -41906s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -41688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -60891s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -100235s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -59250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -96485s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -38188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -37094s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -91485s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35594s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -105282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -34688s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -73985s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -42141s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -82782s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -39141s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36891s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35859s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -46000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -33891s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32859s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -31641s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51485s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48750s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -35188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -51282s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -41250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -31188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -31250s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -59408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -57408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -55408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -78141s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -48908s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -72891s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -45094s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -41908s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -62391s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -38408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -76188s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -36408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -34908s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -34408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32908s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -32408s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\starx.exe TID: 6964Thread sleep time: -47250s >= -30000s