Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA250 CryptAcquireContextA,CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptAcquireContextA,SetLastError,__CxxThrowException@8,CryptAcquireContextA,___std_exception_copy, | 0_2_000CA250 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA8E0 CryptReleaseContext, | 0_2_000CA8E0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA9B0 CryptGenRandom,CryptReleaseContext,__CxxThrowException@8, | 0_2_000CA9B0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA3B0 CryptAcquireContextA,GetLastError,CryptReleaseContext, | 0_2_000CA3B0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA740 CryptReleaseContext, | 0_2_000CA740 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA780 CryptGenRandom,__CxxThrowException@8, | 0_2_000CA780 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CA810 ReleaseMutex,CryptGenRandom,CryptReleaseContext,__CxxThrowException@8, | 0_2_000CA810 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA250 CryptAcquireContextA,CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptAcquireContextA,SetLastError,__CxxThrowException@8,CryptAcquireContextA,___std_exception_copy, | 23_2_000CA250 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA810 ReleaseMutex,CryptGenRandom,CryptReleaseContext,__CxxThrowException@8, | 23_2_000CA810 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA8E0 CryptReleaseContext, | 23_2_000CA8E0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA9B0 CryptGenRandom,CryptReleaseContext,__CxxThrowException@8, | 23_2_000CA9B0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA3B0 CryptAcquireContextA,GetLastError,CryptReleaseContext, | 23_2_000CA3B0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA740 CryptReleaseContext, | 23_2_000CA740 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CA780 CryptGenRandom,__CxxThrowException@8, | 23_2_000CA780 |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://clients1.google.com/ocsp0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://crl.geotrust.com/crls/secureca.crl0N |
Source: LockerGogaRecent.exe | String found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl0= |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: LockerGogaRecent.exe | String found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0# |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://g.symcb.com/crls/gtglobal.crl0 |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://g.symcd.com0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://ocsp.digicert.com0K |
Source: LockerGogaRecent.exe | String found in binary or memory: http://ocsp.sectigo.com0 |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://pki.google.com/GIAG2.crl0 |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://pki.google.com/GIAG2.crt0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://s2.symcb.com0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://s2.symcb.com0k |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://www.symauth.com/cps0( |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: http://www.symauth.com/rpa0) |
Source: tgytutrc3979.exe, 00000022.00000003.2519870637.01D05000.00000004.sdmp | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: LockerGogaRecent.exe | String found in binary or memory: https://sectigo.com/CPS0C |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: tgytutrc3979.exe, 00000022.00000003.2524218394.01D1C000.00000004.sdmp | String found in binary or memory: https://www.geotrust.com/resources/repository0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D1880 | 0_2_000D1880 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B4060 | 0_2_000B4060 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CB07A | 0_2_000CB07A |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000A8150 | 0_2_000A8150 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00128166 | 0_2_00128166 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_0011B2BE | 0_2_0011B2BE |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B42E0 | 0_2_000B42E0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CB422 | 0_2_000CB422 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CC435 | 0_2_000CC435 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B44B0 | 0_2_000B44B0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000785B0 | 0_2_000785B0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B7610 | 0_2_000B7610 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D56F0 | 0_2_000D56F0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_0010E796 | 0_2_0010E796 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B8790 | 0_2_000B8790 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_0009D7B0 | 0_2_0009D7B0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00104830 | 0_2_00104830 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000A6840 | 0_2_000A6840 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00067850 | 0_2_00067850 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00105A63 | 0_2_00105A63 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D5AD0 | 0_2_000D5AD0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00115B00 | 0_2_00115B00 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000C6B10 | 0_2_000C6B10 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000C7BE0 | 0_2_000C7BE0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000A5C20 | 0_2_000A5C20 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_0008FC60 | 0_2_0008FC60 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D3C80 | 0_2_000D3C80 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000A4CC0 | 0_2_000A4CC0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00086CF0 | 0_2_00086CF0 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000CBDC7 | 0_2_000CBDC7 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000B3E50 | 0_2_000B3E50 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D3E60 | 0_2_000D3E60 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_000D5F30 | 0_2_000D5F30 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: 0_2_00107FF7 | 0_2_00107FF7 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000A8150 | 23_2_000A8150 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CC435 | 23_2_000CC435 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0009D7B0 | 23_2_0009D7B0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D1880 | 23_2_000D1880 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0008FC60 | 23_2_0008FC60 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D4040 | 23_2_000D4040 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B4060 | 23_2_000B4060 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000F4159 | 23_2_000F4159 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00128166 | 23_2_00128166 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B42E0 | 23_2_000B42E0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B44B0 | 23_2_000B44B0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000785B0 | 23_2_000785B0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B8790 | 23_2_000B8790 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00104830 | 23_2_00104830 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CC8CF | 23_2_000CC8CF |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D4910 | 23_2_000D4910 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000A4CC0 | 23_2_000A4CC0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000F11D3 | 23_2_000F11D3 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D56F0 | 23_2_000D56F0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0011173B | 23_2_0011173B |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000F19B9 | 23_2_000F19B9 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00105A63 | 23_2_00105A63 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D5AD0 | 23_2_000D5AD0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00115B00 | 23_2_00115B00 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000A5C20 | 23_2_000A5C20 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00105DD5 | 23_2_00105DD5 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D5F30 | 23_2_000D5F30 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0010607F | 23_2_0010607F |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00106346 | 23_2_00106346 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000F6551 | 23_2_000F6551 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00106601 | 23_2_00106601 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0010E796 | 23_2_0010E796 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000A6840 | 23_2_000A6840 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_001228D9 | 23_2_001228D9 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000DAA9B | 23_2_000DAA9B |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000C6B10 | 23_2_000C6B10 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00086CF0 | 23_2_00086CF0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CB07A | 23_2_000CB07A |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CB087 | 23_2_000CB087 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_0011B2BE | 23_2_0011B2BE |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CB422 | 23_2_000CB422 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B7610 | 23_2_000B7610 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00067850 | 23_2_00067850 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000C7BE0 | 23_2_000C7BE0 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000D3C80 | 23_2_000D3C80 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CBDC7 | 23_2_000CBDC7 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000B3E50 | 23_2_000B3E50 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_00107FF7 | 23_2_00107FF7 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: 23_2_000CBFEB | 23_2_000CBFEB |
Source: unknown | Process created: C:\Users\user\Desktop\LockerGogaRecent.exe 'C:\Users\user\Desktop\LockerGogaRecent.exe' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c move /y C:\Users\user\Desktop\LockerGogaRecent.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -m | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | |
Source: unknown | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user Administrator HuHuHUHoHo283283@dJD | |
Source: unknown | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user Administrator HuHuHUHoHo283283@dJD | |
Source: unknown | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user user HuHuHUHoHo283283@dJD | |
Source: unknown | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user user HuHuHUHoHo283283@dJD | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c move /y C:\Users\user\Desktop\LockerGogaRecent.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe | Jump to behavior |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -m | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c move /y C:\Users\user\Desktop\LockerGogaRecent.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe | Jump to behavior |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -m | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe C:\Users\user~1\AppData\Local\Temp\tgytutrc3979.exe -i SM-tgytutrc -s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\logoff.exe C:\Windows\system32\logoff.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net.exe C:\Windows\system32\net.exe user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user Administrator HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 user user HuHuHUHoHo283283@dJD | Jump to behavior |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 0_2_0012719B |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 0_2_0012736F |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: GetLocaleInfoW, | 0_2_0011F384 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, | 0_2_00126A37 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: EnumSystemLocalesW, | 0_2_00126CAF |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: EnumSystemLocalesW, | 0_2_00126CFA |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: EnumSystemLocalesW, | 0_2_00126D95 |
Source: C:\Users\user\Desktop\LockerGogaRecent.exe | Code function: EnumSystemLocalesW, | 0_2_0011EE9B |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW, | 23_2_000ECCEE |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: ___crtGetLocaleInfoEx, | 23_2_000ECDE7 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, | 23_2_00126A37 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: EnumSystemLocalesW, | 23_2_00126CAF |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: EnumSystemLocalesW, | 23_2_00126CFA |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: EnumSystemLocalesW, | 23_2_00126D95 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 23_2_00126E22 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: EnumSystemLocalesW, | 23_2_0011EE9B |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW, | 23_2_00127072 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 23_2_0012719B |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW, | 23_2_001272A2 |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 23_2_0012736F |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Code function: GetLocaleInfoW, | 23_2_0011F384 |
Source: C:\Windows\System32\cmd.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\IlsCache\ilrcache.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000b.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\resource.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\branding.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\AccessMUISet.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\angular.js VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\ZGGKNSUKOP.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\JDDHMPCDUJ.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\ZGGKNSUKOP.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proofing.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-latest.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\IlsCache\imcrcache.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUISet.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Office\ONetConfig\b6419f5bc3093b5f22142ce454e02407.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows Mail\oeold.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\TM01793060[[fn=Origin]].dotx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\DUUDTUBZFW\DUUDTUBZFW.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\{67D69890-D853-4011-A87E-AA64FA83CE5A}.2.ver0x0000000000000002.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2015-03-09.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\resource.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\background_script.js VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PowerPointMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\branding.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlookMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2011-04-08.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Caches\{86012F79-362C-43D2-98EF-AB58A0A31343}.2.ver0x0000000000000001.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PublisherMUI.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SingleImageWW.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\Setup.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Office64WW.xml VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\ZGGKNSUKOP\ZGGKNSUKOP.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\KLIZUSIQEN.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EWZCVGNOWT.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\DUUDTUBZFW\ZGGKNSUKOP.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EWZCVGNOWT\JDDHMPCDUJ.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\KLIZUSIQEN.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EWZCVGNOWT.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EOWRVPQCCS\EOWRVPQCCS.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\DUUDTUBZFW.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\blocklist.xml VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\ZGGKNSUKOP.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\NWCXBPIUYI.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EIVQSAOTAQ\KLIZUSIQEN.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\DUUDTUBZFW.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EIVQSAOTAQ\QCOILOQIKC.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\QCOILOQIKC.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EOWRVPQCCS\GIGIYTFFYT.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\secmod.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\sessionstore-backups\previous.js VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\ZGGKNSUKOP\KLIZUSIQEN.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\QCOILOQIKC.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\DUUDTUBZFW\EOWRVPQCCS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EWZCVGNOWT.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EOWRVPQCCS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EIVQSAOTAQ\EIVQSAOTAQ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\JDDHMPCDUJ.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EWZCVGNOWT\NWCXBPIUYI.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EOWRVPQCCS.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EOWRVPQCCS\EIVQSAOTAQ.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EIVQSAOTAQ\KLIZUSIQEN.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\KLIZUSIQEN.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\ZGGKNSUKOP\EWZCVGNOWT.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EWZCVGNOWT\JDDHMPCDUJ.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EIVQSAOTAQ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\cert8.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\GIGIYTFFYT.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EWZCVGNOWT\EWZCVGNOWT.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\DUUDTUBZFW\DUUDTUBZFW.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EIVQSAOTAQ\EIVQSAOTAQ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\key3.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EWZCVGNOWT\NWCXBPIUYI.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EIVQSAOTAQ\QCOILOQIKC.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Documents\EWZCVGNOWT\EWZCVGNOWT.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\22qkc0w7.default\prefs.js VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\NWCXBPIUYI.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EIVQSAOTAQ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EOWRVPQCCS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\EIVQSAOTAQ.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\DUUDTUBZFW\EOWRVPQCCS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\Desktop\DUUDTUBZFW\ZGGKNSUKOP.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\IconCache.db VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\opatchinstall(3).log VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\ProgramData\Microsoft\OFFICE\UICaptions\1036\WWINTL.DLL.trx_dll VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Roaming\.jre\bin\prism_sw.dll VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Temp\tgytutrc3979.exe | Queries volume information: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\22qkc0w7.default\cache2\entries\D85795856A15100A0C45C075CFB29C4FC314C2EE VolumeInformation | |