| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619401376.083999 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619401376.083999 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| domain | alhabib4rec.ddns.net |
| domain | alhabib4rec.duckdns.org |
| description | RegSvcs.exe tried to sleep 158 seconds, actually delayed analysis time by 158 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\vhakvhosb.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\hxnfgb.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\oaclraip.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\cand.ppt |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\dktnmekixe.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\xxohj.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\lqen.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\cnsqlfhqgw.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\kehniguoe.ppt |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\tlpmgdweq.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\imfcga.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\igqvkrqcj.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\cxqsmqjdv.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\tlpmgdweq.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\59909268\tlpmgdweq.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: cb6c427c26c95e8963eb2437b2dd357f36693b75 |
| buffer | Buffer with sha1: 9b2a8f15915e38fcc8520a9438ef8e5ba5dbe8a5 |
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | C:\Users\ADMINI~1.OSK\AppData\Roaming\59909268\TLPMGD~1.PIF C:\Users\ADMINI~1.OSK\AppData\Roaming\59909268\nlncgw.ath | ||||||