File name:

eDEX-UI-Windows-x64.exe

Full analysis: https://app.any.run/tasks/2346fb59-12b1-421a-991f-e21ac6a2ccf9
Verdict: Malicious activity
Analysis date: December 09, 2024, 00:33:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

20BEFF9C4CC991A27DBC24E61067F37F

SHA1:

0C65AD7D5F4A58BE8533ACA3E1477FADBC41C663

SHA256:

E877429D2AFFF2977497E4C9C379B2C6A140143D7DF19478344871E05BE8AD6C

SSDEEP:

1572864:imSHpRoERp4sheNfEvU08MCPcAMAyAYaCb:imSJRoERp4s4NsvU08MucVBAYaU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Unrestricted)

      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Executable content was dropped or overwritten

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • The process creates files with name similar to system file names

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Drops 7-zip archiver for unpacking

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Process drops legitimate windows executable

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Reads security settings of Internet Explorer

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Creates a software uninstall entry

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Application launched itself

      • eDEX-UI.exe (PID: 6704)
    • Starts POWERSHELL.EXE for commands execution

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
    • Starts CMD.EXE for commands execution

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
    • Starts application with an unusual extension

      • cmd.exe (PID: 6908)
      • cmd.exe (PID: 6088)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 536)
      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 540)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 8676)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 8132)
    • The process hides Powershell's copyright startup banner

      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
    • Uses WMIC.EXE to obtain data on processes

      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 4160)
    • Uses WMIC.EXE to obtain information about the network interface controller

      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 1468)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 7040)
      • cmd.exe (PID: 7540)
      • cmd.exe (PID: 7764)
      • cmd.exe (PID: 7352)
      • cmd.exe (PID: 6464)
      • cmd.exe (PID: 6984)
      • cmd.exe (PID: 7580)
      • cmd.exe (PID: 7476)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 6540)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 6412)
      • cmd.exe (PID: 9116)
      • cmd.exe (PID: 8924)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 9124)
      • cmd.exe (PID: 8828)
      • cmd.exe (PID: 7636)
      • cmd.exe (PID: 7488)
      • cmd.exe (PID: 8540)
      • cmd.exe (PID: 3552)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 8880)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7560)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 8044)
      • cmd.exe (PID: 8936)
      • cmd.exe (PID: 8212)
      • cmd.exe (PID: 9012)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 8884)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 3220)
      • cmd.exe (PID: 900)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 1144)
      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 3992)
      • cmd.exe (PID: 7560)
      • cmd.exe (PID: 6484)
      • cmd.exe (PID: 6004)
      • cmd.exe (PID: 8912)
      • cmd.exe (PID: 1536)
      • cmd.exe (PID: 5156)
      • cmd.exe (PID: 9184)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 8884)
      • cmd.exe (PID: 7068)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 8344)
      • cmd.exe (PID: 8852)
      • cmd.exe (PID: 8212)
      • cmd.exe (PID: 1796)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 7588)
      • cmd.exe (PID: 8924)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 4144)
      • cmd.exe (PID: 8340)
      • cmd.exe (PID: 8432)
      • cmd.exe (PID: 6896)
      • cmd.exe (PID: 8748)
      • cmd.exe (PID: 1412)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 7980)
      • cmd.exe (PID: 1172)
      • cmd.exe (PID: 5400)
      • cmd.exe (PID: 4132)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 7728)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 5036)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 7736)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 7380)
      • cmd.exe (PID: 2456)
      • cmd.exe (PID: 7324)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 2396)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 1144)
      • cmd.exe (PID: 2796)
      • cmd.exe (PID: 7720)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 7688)
      • cmd.exe (PID: 9004)
    • Uses WMIC.EXE to obtain data on the virtual memory file swapping

      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 8172)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 8676)
    • Uses WMIC.EXE

      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 9160)
    • Uses WMIC.EXE to obtain local storage devices information

      • cmd.exe (PID: 536)
      • cmd.exe (PID: 3124)
    • Uses NETSH.EXE to obtain data on the network

      • cmd.exe (PID: 1348)
      • cmd.exe (PID: 1888)
      • cmd.exe (PID: 7996)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 2408)
      • cmd.exe (PID: 2572)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 8748)
      • cmd.exe (PID: 8396)
      • cmd.exe (PID: 8360)
      • cmd.exe (PID: 6220)
      • cmd.exe (PID: 4076)
      • cmd.exe (PID: 7440)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 7484)
      • cmd.exe (PID: 5604)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 8620)
      • cmd.exe (PID: 7704)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 9016)
      • cmd.exe (PID: 8416)
      • cmd.exe (PID: 9024)
      • cmd.exe (PID: 8904)
      • cmd.exe (PID: 7752)
      • cmd.exe (PID: 2324)
      • cmd.exe (PID: 6896)
      • cmd.exe (PID: 8828)
      • cmd.exe (PID: 6180)
      • cmd.exe (PID: 8396)
      • cmd.exe (PID: 5236)
      • cmd.exe (PID: 7312)
      • cmd.exe (PID: 8616)
      • cmd.exe (PID: 8352)
      • cmd.exe (PID: 7792)
      • cmd.exe (PID: 7320)
      • cmd.exe (PID: 7440)
      • cmd.exe (PID: 6264)
      • cmd.exe (PID: 1888)
      • cmd.exe (PID: 1292)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 5728)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 6464)
      • cmd.exe (PID: 4628)
      • cmd.exe (PID: 1536)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8128)
    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 3680)
      • cmd.exe (PID: 6500)
      • cmd.exe (PID: 5460)
      • cmd.exe (PID: 7316)
      • cmd.exe (PID: 7012)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 8504)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8664)
      • cmd.exe (PID: 2324)
      • cmd.exe (PID: 7112)
      • cmd.exe (PID: 6840)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 9212)
      • cmd.exe (PID: 4908)
      • cmd.exe (PID: 8224)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 3612)
      • cmd.exe (PID: 432)
      • cmd.exe (PID: 8784)
      • cmd.exe (PID: 6216)
      • cmd.exe (PID: 8984)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 8344)
      • cmd.exe (PID: 880)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 7412)
      • cmd.exe (PID: 7932)
      • cmd.exe (PID: 3992)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 8024)
      • cmd.exe (PID: 7808)
      • cmd.exe (PID: 8444)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 7336)
      • cmd.exe (PID: 4036)
      • cmd.exe (PID: 8168)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 9084)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 3928)
      • cmd.exe (PID: 6552)
      • cmd.exe (PID: 6944)
      • cmd.exe (PID: 8440)
      • cmd.exe (PID: 7484)
      • cmd.exe (PID: 8500)
      • cmd.exe (PID: 9044)
      • cmd.exe (PID: 4996)
    • Uses WMIC.EXE to obtain CPU information

      • cmd.exe (PID: 540)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 9056)
    • Executes as Windows Service

      • WmiApSrv.exe (PID: 6500)
    • Uses WMIC.EXE to obtain BIOS management information

      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 8132)
  • INFO

    • Checks supported languages

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7052)
      • chcp.com (PID: 7008)
      • eDEX-UI.exe (PID: 1596)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 2216)
      • eDEX-UI.exe (PID: 6816)
      • chcp.com (PID: 5460)
      • chcp.com (PID: 848)
      • eDEX-UI.exe (PID: 2084)
      • chcp.com (PID: 6200)
      • chcp.com (PID: 6544)
    • Reads the computer name

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 6816)
      • eDEX-UI.exe (PID: 1596)
      • eDEX-UI.exe (PID: 2084)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 2216)
    • Create files in a temporary directory

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
    • Creates files or folders in the user directory

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 1596)
    • Manual execution by a user

      • eDEX-UI.exe (PID: 6704)
    • Reads product name

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 2216)
    • Reads Environment values

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 2216)
    • Drops encrypted VBS script (Microsoft Script Encoder)

      • eDEX-UI.exe (PID: 6704)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • eDEX-UI.exe (PID: 6704)
    • Reads CPU info

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7052)
    • Changes the display of characters in the console

      • cmd.exe (PID: 6908)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6088)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 536)
      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 540)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 8676)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9056)
    • Checks proxy server information

      • eDEX-UI.exe (PID: 6704)
    • Process checks computer location settings

      • eDEX-UI.exe (PID: 2216)
      • eDEX-UI.exe (PID: 6704)
    • The process uses the downloaded file

      • powershell.exe (PID: 6856)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 6856)
    • Node.js compiler has been detected

      • eDEX-UI.exe (PID: 6704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:02:12 16:15:17+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 30208
InitializedDataSize: 483840
UninitializedDataSize: 16384
EntryPoint: 0x39ed
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.2.8.0
ProductVersionNumber: 2.2.8.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Gabriel 'Squared' SAILLARD
FileDescription: eDEX-UI sci-fi interface
FileVersion: 2.2.8
LegalCopyright: Copyright © 2017-2021 Gabriel 'Squared' SAILLARD <gabriel@saillard.dev> (https://gaby.dev)
ProductName: eDEX-UI
ProductVersion: 2.2.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
1 799
Monitored processes
1 684
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start edex-ui-windows-x64.exe edex-ui.exe no specs edex-ui.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs comppkgsrv.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs edex-ui.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs reg.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmiapsrv.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netsh.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs netstat.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs reg.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netstat.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs ipconfig.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs chcp.com no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs conhost.exe no specs netstat.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs ipconfig.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs netsh.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs wmic.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs cmd.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs reg.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs wmic.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs wmic.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs ipconfig.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs reg.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs edex-ui.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
244C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /valueC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
244C:\WINDOWS\system32\cmd.exe /d /s /c "C:\WINDOWS\system32\chcp.com 65001 | C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /value"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
244C:\WINDOWS\system32\cmd.exe /d /s /c "ipconfig /all"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
308\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
308powershell.exe -NoLogo -InputFormat Text -NoExit -ExecutionPolicy Unrestricted -Command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432C:\WINDOWS\system32\cmd.exe /d /s /c "ipconfig /all"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /valueC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
440\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
114 768
Read events
114 736
Write events
14
Delete events
18

Modification events

(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\eDEX-UI
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:ShortcutName
Value:
eDEX-UI
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayName
Value:
eDEX-UI 2.2.8
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\eDEX-UI\Uninstall eDEX-UI.exe" /currentuser
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\eDEX-UI\Uninstall eDEX-UI.exe" /currentuser /S
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayVersion
Value:
2.2.8
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\eDEX-UI\eDEX-UI.exe,0
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:Publisher
Value:
Gabriel 'Squared' SAILLARD
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:NoModify
Value:
1
Executable files
22
Suspicious files
119
Text files
292
Unknown types
61

Dropped files

PID
Process
Filename
Type
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\app-64.7z
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\icudtl.dat
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\LICENSES.chromium.html
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\nsis7z.dllexecutable
MD5:80E44CE4895304C6A3A831310FBF8CD0
SHA256:B393F05E8FF919EF071181050E1873C9A776E1A0AE8329AEFFF7007D0CADF592
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\LICENSE.electron.txttext
MD5:45574510C534A8195F53B30E3810239E
SHA256:C44607A865E7A6DB05552BAA0EF71F9887D96ACD00D123854B44996BC27C0E33
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\modern-wizard.bmpimage
MD5:52FF52EEE3B944B862C11C268A02C196
SHA256:2079F7A3EBA60E0D9EE827A7208AA052A71B384873B641DE5E299AEB8E733109
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\chrome_200_percent.pakpgc
MD5:1985B8FC603DB4D83DF72CFAEEAC7C50
SHA256:7F9DED50D81C50F9C6ED89591FA621FABBD45CEF150C8AABCCEB3B7A9DE5603B
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\locales\ar.pakpgc
MD5:70BB1C831327B26E4DD74097F59A55B0
SHA256:776DB47DD91BCE8BC813A54A815BE3E73B6E58E9FE5F24DB7BF0D8C06A240F6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
65
DNS requests
9
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
204
104.126.37.145:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
2216
eDEX-UI.exe
185.199.108.133:443
raw.githubusercontent.com
FASTLY
US
shared
2216
eDEX-UI.exe
140.82.121.5:443
api.github.com
GITHUB
US
whitelisted
2216
eDEX-UI.exe
1.1.1.1:80
CLOUDFLARENET
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.176
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.140
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared
api.github.com
  • 140.82.121.5
whitelisted
self.events.data.microsoft.com
  • 20.189.173.26
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info