Summary | ZeroBOX

My_Map.scr

RedLine Infostealer Gen1 UltraVNC UPX Malicious Library Malicious Packer Anti_VM PE File OS Processor Check PE32 DLL
Category Machine Started Completed
FILE s1_win7_x6403_us July 19, 2023, 9:04 a.m. July 19, 2023, 9:07 a.m.
Size 526.4KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 33647ca452ca1a5d88fa6f08aa6f146c
SHA256 4a7df87d066283f4ab2f2ac72495fb3deaf127e0175572480d8bce6873ea637a
CRC32 430C8165
ssdeep 12288:bh1Lk70TnvjcHO5yWWK8u/RsAPpw9WWyDbObRryp+TM6F:nk70TrcO/pPpwYDbOR8+TM6F
PDB Path
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • MALWARE_Win_VT_RedLine - Detects RedLine infostealer
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • UltraVNC_Zero - UltraVNC
  • IsPE32 - (no description)

IP Address Status Action
116.202.177.109 Active Moloch
149.154.167.99 Active Moloch
164.124.101.2 Active Moloch
23.34.107.26 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49164 -> 149.154.167.99:443 2041933 ET INFO Observed Telegram Domain (t .me in TLS SNI) Misc activity
TCP 192.168.56.103:49164 -> 149.154.167.99:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49164 -> 149.154.167.99:443 2041933 ET INFO Observed Telegram Domain (t .me in TLS SNI) Misc activity
TCP 192.168.56.103:49165 -> 149.154.167.99:443 2041933 ET INFO Observed Telegram Domain (t .me in TLS SNI) Misc activity
TCP 192.168.56.103:49165 -> 149.154.167.99:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49168 -> 23.34.107.26:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49165 -> 149.154.167.99:443 2041933 ET INFO Observed Telegram Domain (t .me in TLS SNI) Misc activity
TCP 149.154.167.99:443 -> 192.168.56.103:49166 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.103:49170 -> 116.202.177.109:80 2027262 ET INFO Dotted Quad Host ZIP Request Potentially Bad Traffic
TCP 192.168.56.103:49164 -> 149.154.167.99:443 2041933 ET INFO Observed Telegram Domain (t .me in TLS SNI) Misc activity

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49168
23.34.107.26:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com b1:30:5e:4c:ee:14:70:87:a7:d7:1c:77:07:b5:3c:2c:99:13:aa:c5

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540e90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540e90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540ed0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540ed0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540fd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540fd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540fd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00540fd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00541090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00541090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00541090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00541090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
pdb_path
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 07 66 0f 7f 47 10 66 0f 7f 47 20 66 0f
exception.symbol: my_map+0xefe7
exception.address: 0x40efe7
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61415
registers.esp: 1636976
registers.edi: 4363280
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2849
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4366224
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2826
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4370320
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2794
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4374416
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2762
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4378512
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2730
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4382608
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2698
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4386704
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2666
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4390800
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2634
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4394896
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2602
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4398992
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2570
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4403088
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2538
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4407184
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2506
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4411280
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2474
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4415376
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2442
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4419472
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2410
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4423568
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2378
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4427664
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2346
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4431760
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2314
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4435856
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2282
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4439952
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2250
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4444048
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2218
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4448144
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2186
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4452240
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2154
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4456336
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2122
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4460432
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2090
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4464528
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2058
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4468624
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 2026
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4472720
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1994
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4476816
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1962
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4480912
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1930
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4485008
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1898
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4489104
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1866
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4493200
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1834
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4497296
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1802
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4501392
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1770
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4505488
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1738
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4509584
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1706
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4513680
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1674
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4517776
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1642
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4521872
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1610
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4525968
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1578
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4530064
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1546
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4534160
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1514
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4538256
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1482
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4542352
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1450
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4546448
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1418
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4550544
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1386
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4554640
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1354
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4558736
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1322
1 0 0

__exception__

stacktrace:
my_map+0xf054 @ 0x40f054
my_map+0x1fa2 @ 0x401fa2

exception.instruction_r: 66 0f 7f 47 70 8d bf 80 00 00 00 49 75 d0 8b 7d
exception.symbol: my_map+0xf009
exception.address: 0x40f009
exception.module: My_Map.scr
exception.exception_code: 0xc0000005
exception.offset: 61449
registers.esp: 1636976
registers.edi: 4562832
registers.eax: 4363280
registers.ebp: 1636980
registers.edx: 70
registers.ebx: 0
registers.esi: 33030216
registers.ecx: 1290
1 0 0
suspicious_features Connection to IP address suspicious_request GET http://116.202.177.109/c2413e9d86eb61b5af540798875f05ed
suspicious_features Connection to IP address suspicious_request GET http://116.202.177.109/upgrade.zip
suspicious_features POST method with no referer header, Connection to IP address suspicious_request POST http://116.202.177.109/
request GET http://116.202.177.109/c2413e9d86eb61b5af540798875f05ed
request GET http://116.202.177.109/upgrade.zip
request POST http://116.202.177.109/
request GET https://steamcommunity.com/profiles/76561198982268531
request POST http://116.202.177.109/
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 1441792
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02280000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 917504
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02280000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02320000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73eb1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73eb2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 2162688
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02580000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02750000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02321000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02322000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004ea000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004ec000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02323000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004fc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02324000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0061b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00617000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02700000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00615000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 53248
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02701000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0270e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00506000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0050a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00507000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0270f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f81000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f82000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f84000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0272f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02720000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1616
region_size: 28672
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f85000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2140
region_size: 995328
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x61e00000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Local Extension Settings\cjmkndjhnagcfbpiemnkdpomccnjblmj\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\4.10.2391.0\_platform_specific\win_x64\widevinecdm.dll.sig\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Local Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\4\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Module Info Cache\IndexedDB\chrome-extension_hpglfhgfnhbgpjdenjgmdgoeiappafln_0.indexeddb.leveldb\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\th\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\000003.log\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\iw\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Module Info Cache\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\uk\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Local Extension Settings\bgpipimickeadkjlklgciifhnalhdjhe\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdo\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Local Extension Settings\epapihdplajcdnnkdeiahlgigofloibg\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\it\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Local Extension Settings\oeljdldpnmdbchonielidgobddffflal\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Subresource Filter\Local Extension Settings\fmhmiaejopepamlcjkncpgpdjichnecm\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\IndexedDB\chrome-extension_hpglfhgfnhbgpjdenjgmdgoeiappafln_0.indexeddb.leveldb\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\zh_CN\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Last Version\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Channel IDs\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crowd Deny\Sync Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Local Extension Settings\gjagmgiddbbciopjhllkdnddhcglnemk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\es_419\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal\Local Extension Settings\oeljdldpnmdbchonielidgobddffflal\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Local Extension Settings\fmhmiaejopepamlcjkncpgpdjichnecm\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\lo\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\03019df3fd85a69a8ebd1facc6da9ba73e469774fe77f579fc5a08b8328c1d6b.sth\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\1\english_wikipedia.txt\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\GPUCache\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_2\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Local Extension Settings\aijcbedoijmgnlmjeegjaglmepbmpkpi\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Local Extension Settings\pdadjkfkgcafgbceimcpbkalnfnepbnk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Local Extension Settings\gjagmgiddbbciopjhllkdnddhcglnemk\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Sync Extension Settings\oeljdldpnmdbchonielidgobddffflal\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\52\manifest.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\ka\messages.json\Network\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\CURRENT
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\tr\Network\Cookies
file C:\ProgramData\freebl3.dll
file C:\ProgramData\msvcp140.dll
file C:\Windows\Temp\1.exe
file C:\ProgramData\nss3.dll
file C:\ProgramData\vcruntime140.dll
file C:\ProgramData\mozglue.dll
file C:\ProgramData\softokn3.dll
file C:\Windows\Temp\1.exe
wmi
wmi Select * From Win32_OperatingSystemInstallDate湕湫
section {u'size_of_data': u'0x0005cc00', u'virtual_address': u'0x00026000', u'entropy': 7.998310735909361, u'name': u'.rsrc', u'virtual_size': u'0x0005ca64'} entropy 7.99831073591 description A section with a high entropy has been found
entropy 0.733201581028 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
Time & API Arguments Status Return Repeated

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000057c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EditPlus
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EditPlus
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Haansoft HWord 80 Korean
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Haansoft HWord 80 Korean
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Thunderbird 78.4.0 (x86 ko)
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Thunderbird 78.4.0 (x86 ko)
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.PROPLUSR
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.PROPLUSR
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00203668-8170-44A0-BE44-B632FA4D780F}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00203668-8170-44A0-BE44-B632FA4D780F}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D91F7DA-F517-4727-9E62-B7EA978BE980}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D91F7DA-F517-4727-9E62-B7EA978BE980}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F32180131F0}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F32180131F0}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0015-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0015-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0016-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0016-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0018-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0018-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0019-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0019-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001A-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001A-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001B-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001B-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-040C-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-040C-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0C0A-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0C0A-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-002C-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-002C-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0044-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0044-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-006E-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-006E-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0090-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0090-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00A1-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00A1-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00BA-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00BA-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E1-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E1-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E2-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E2-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0115-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0115-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0117-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0117-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-012B-0409-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-012B-0409-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91150000-0011-0000-0000-0000000FF1CE}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91150000-0011-0000-0000-0000000FF1CE}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{939659F3-71D2-461F-B24D-91D05A4389B4}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{939659F3-71D2-461F-B24D-91D05A4389B4}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9B84A461-3B4C-40E2-B44F-CE22E215EE40}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9B84A461-3B4C-40E2-B44F-CE22E215EE40}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}
1 0 0

RegOpenKeyExA

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB8B979E-E336-47E7-96BC-1031C1B94561}
base_handle: 0x80000002
key_handle: 0x0000058c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB8B979E-E336-47E7-96BC-1031C1B94561}
1 0 0
host 116.202.177.109
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
file C:\Users\test22\AppData\Roaming\Electrum\wallets\??????
file C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml
registry HKEY_CURRENT_USER\Software\Martin Prikryl\WinSCP 2\Configuration
Time & API Arguments Status Return Repeated

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: 7-Zip 20.02 alpha
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Adobe AIR
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: EditPlus
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EditPlus\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Chrome
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: ????? ?? 2010
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Haansoft HWord 80 Korean\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Mozilla Thunderbird 78.4.0 (x86 ko)
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Thunderbird 78.4.0 (x86 ko)\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Professional Plus 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office15.PROPLUSR\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Adobe AIR
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{00203668-8170-44A0-BE44-B632FA4D780F}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: HttpWatch Professional 9.3.39
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: ????? ?? 2010
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D91F7DA-F517-4727-9E62-B7EA978BE980}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Java 8 Update 131
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F32180131F0}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Java Auto Updater
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Google Update Helper
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Access MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0015-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Excel MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0016-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft PowerPoint MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0018-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Publisher MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0019-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Outlook MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001A-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Word MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001B-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Proofing Tools 2013 - English
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Outils de vérification linguistique 2013 de Microsoft Office - Français
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-040C-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Proofing Tools 2013 - Español
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-001F-0C0A-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Proofing (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-002C-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft InfoPath MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0044-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Shared MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-006E-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft DCF MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0090-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft OneNote MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00A1-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Groove MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00BA-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office OSM MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E1-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office OSM UX MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-00E2-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Shared Setup Metadata MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0115-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Access Setup Metadata MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-0117-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Lync MUI (English) 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-012B-0409-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Office Professional Plus 2013
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{91150000-0011-0000-0000-0000000FF1CE}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Adobe Flash Player 13 ActiveX
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{939659F3-71D2-461F-B24D-91D05A4389B4}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Adobe Flash Player 13 NPAPI
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9B84A461-3B4C-40E2-B44F-CE22E215EE40}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Adobe Acrobat Reader DC MUI
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\DisplayName
1 0 0

RegQueryValueExA

key_handle: 0x0000058c
regkey_r: DisplayName
reg_type: 1 (REG_SZ)
value: Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{d992c12e-cab2-426f-bde3-fb8c53950b0d}\DisplayName
1 0 0
file C:\Users\test22\AppData\Roaming\Thunderbird\profiles.ini
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
process 1.exe useragent Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0
process 1.exe useragent Mozilla/5.0 (X11; Linux 3.5.4-1-ARCH i686; es) KHTML/4.9.1 (like Gecko) Konqueror/4.9
Cynet Malicious (score: 100)
McAfee Artemis!33647CA452CA
Sangfor Trojan.Win32.Agent.Vzx9
Cyren W32/MSIL_Agent.CJU.gen!Eldorado
APEX Malicious
Kaspersky UDS:Trojan-PSW.Win32.Stealerc
Avast FileRepMalware [Pws]
F-Secure Heuristic.HEUR/AGEN.1327060
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
Sophos Mal/Generic-S
Avira HEUR/AGEN.1327060
Microsoft Trojan:Win32/Leonem
ZoneAlarm UDS:Trojan-PSW.Win32.Stealerc
Google Detected
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
BitDefenderTheta Gen:NN.ZexaF.36318.Gq2@aW9HzKb
AVG FileRepMalware [Pws]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)