| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620842935.035999 IsDebuggerPresent |
failed | 0 | 0 | |
|
1620842935.066999 IsDebuggerPresent |
failed | 0 | 0 | |
|
1620842951.379876 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\ptwh.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\xtvgxflad.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\arlrkesbnr.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\oorx.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\lcfvvcrhg.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\irplieb.cpl |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\kfufifvddx.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\irdouwnx.vbs |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\kfufifvddx.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\14478533\kfufifvddx.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: e52591bf46170f08484fce6d0bd1c14991f77a9c |
| buffer | Buffer with sha1: c0452df27eac64a3597127c679a7af6bc078fc9e |
| host | 154.16.93.174 | |||
| host | 172.217.24.14 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | 0\14478533\kfufifvddx.pif 0\14478533\wulgxxw.rhb | ||||||