File name:

eDEX-UI-Windows-x64.exe

Full analysis: https://app.any.run/tasks/2346fb59-12b1-421a-991f-e21ac6a2ccf9
Verdict: Malicious activity
Analysis date: December 09, 2024, 00:33:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

20BEFF9C4CC991A27DBC24E61067F37F

SHA1:

0C65AD7D5F4A58BE8533ACA3E1477FADBC41C663

SHA256:

E877429D2AFFF2977497E4C9C379B2C6A140143D7DF19478344871E05BE8AD6C

SSDEEP:

1572864:imSHpRoERp4sheNfEvU08MCPcAMAyAYaCb:imSJRoERp4s4NsvU08MucVBAYaU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Unrestricted)

      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Drops 7-zip archiver for unpacking

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Process drops legitimate windows executable

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Executable content was dropped or overwritten

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Reads security settings of Internet Explorer

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • The process creates files with name similar to system file names

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Creates a software uninstall entry

      • eDEX-UI-Windows-x64.exe (PID: 6472)
    • Application launched itself

      • eDEX-UI.exe (PID: 6704)
    • Starts CMD.EXE for commands execution

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7072)
    • Starts POWERSHELL.EXE for commands execution

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
    • Starts application with an unusual extension

      • cmd.exe (PID: 6908)
      • cmd.exe (PID: 6088)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 536)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 540)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 8676)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9056)
    • The process hides Powershell's copyright startup banner

      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
    • Uses WMIC.EXE to obtain data on processes

      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 4160)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 8676)
    • Uses WMIC.EXE to obtain data on the virtual memory file swapping

      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 8172)
    • Uses WMIC.EXE

      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 9160)
    • Uses WMIC.EXE to obtain local storage devices information

      • cmd.exe (PID: 536)
      • cmd.exe (PID: 3124)
    • Uses WMIC.EXE to obtain information about the network interface controller

      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 1468)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 7040)
      • cmd.exe (PID: 7764)
      • cmd.exe (PID: 7540)
      • cmd.exe (PID: 7352)
      • cmd.exe (PID: 6464)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 7580)
      • cmd.exe (PID: 7476)
      • cmd.exe (PID: 6540)
      • cmd.exe (PID: 6984)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8212)
      • cmd.exe (PID: 8924)
      • cmd.exe (PID: 9116)
      • cmd.exe (PID: 6412)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 9124)
      • cmd.exe (PID: 8828)
      • cmd.exe (PID: 7636)
      • cmd.exe (PID: 8540)
      • cmd.exe (PID: 3552)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 8880)
      • cmd.exe (PID: 7488)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7560)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 8936)
      • cmd.exe (PID: 8044)
      • cmd.exe (PID: 9012)
      • cmd.exe (PID: 8212)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 8884)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 3220)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 900)
      • cmd.exe (PID: 7560)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 1144)
      • cmd.exe (PID: 6484)
      • cmd.exe (PID: 3992)
      • cmd.exe (PID: 3912)
      • cmd.exe (PID: 8912)
      • cmd.exe (PID: 6004)
      • cmd.exe (PID: 1536)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 5156)
      • cmd.exe (PID: 9184)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 8884)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 8344)
      • cmd.exe (PID: 7068)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 1796)
      • cmd.exe (PID: 8924)
      • cmd.exe (PID: 8852)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 7588)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 8340)
      • cmd.exe (PID: 4144)
      • cmd.exe (PID: 8432)
      • cmd.exe (PID: 6896)
      • cmd.exe (PID: 8748)
      • cmd.exe (PID: 7980)
      • cmd.exe (PID: 1412)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 1172)
      • cmd.exe (PID: 5400)
      • cmd.exe (PID: 4132)
      • cmd.exe (PID: 7728)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 5036)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 7324)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 7736)
      • cmd.exe (PID: 7380)
      • cmd.exe (PID: 2456)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 2396)
      • cmd.exe (PID: 1144)
      • cmd.exe (PID: 7688)
      • cmd.exe (PID: 2796)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 7720)
    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 3680)
      • cmd.exe (PID: 6500)
      • cmd.exe (PID: 5460)
      • cmd.exe (PID: 7316)
      • cmd.exe (PID: 7012)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 8504)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8664)
      • cmd.exe (PID: 2324)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 7112)
      • cmd.exe (PID: 6840)
      • cmd.exe (PID: 9212)
      • cmd.exe (PID: 4908)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 8224)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 3612)
      • cmd.exe (PID: 8784)
      • cmd.exe (PID: 432)
      • cmd.exe (PID: 6216)
      • cmd.exe (PID: 8984)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 8344)
      • cmd.exe (PID: 880)
      • cmd.exe (PID: 7412)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 7932)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 3992)
      • cmd.exe (PID: 7808)
      • cmd.exe (PID: 8024)
      • cmd.exe (PID: 8444)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 7336)
      • cmd.exe (PID: 4036)
      • cmd.exe (PID: 8168)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 9084)
      • cmd.exe (PID: 3928)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 6552)
      • cmd.exe (PID: 6944)
      • cmd.exe (PID: 8440)
      • cmd.exe (PID: 7484)
      • cmd.exe (PID: 8500)
      • cmd.exe (PID: 9044)
      • cmd.exe (PID: 4996)
    • Uses NETSH.EXE to obtain data on the network

      • cmd.exe (PID: 1888)
      • cmd.exe (PID: 1348)
      • cmd.exe (PID: 7996)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 2572)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 2408)
      • cmd.exe (PID: 8748)
      • cmd.exe (PID: 8396)
      • cmd.exe (PID: 6220)
      • cmd.exe (PID: 8360)
      • cmd.exe (PID: 7440)
      • cmd.exe (PID: 8004)
      • cmd.exe (PID: 4076)
      • cmd.exe (PID: 7484)
      • cmd.exe (PID: 5604)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 8620)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7704)
      • cmd.exe (PID: 8416)
      • cmd.exe (PID: 9016)
      • cmd.exe (PID: 7752)
      • cmd.exe (PID: 8904)
      • cmd.exe (PID: 9024)
      • cmd.exe (PID: 2324)
      • cmd.exe (PID: 8828)
      • cmd.exe (PID: 6180)
      • cmd.exe (PID: 6896)
      • cmd.exe (PID: 8396)
      • cmd.exe (PID: 7312)
      • cmd.exe (PID: 5236)
      • cmd.exe (PID: 7792)
      • cmd.exe (PID: 8616)
      • cmd.exe (PID: 8352)
      • cmd.exe (PID: 7320)
      • cmd.exe (PID: 7440)
      • cmd.exe (PID: 6264)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 1888)
      • cmd.exe (PID: 1292)
      • cmd.exe (PID: 5728)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 6464)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 1536)
      • cmd.exe (PID: 4628)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8128)
    • Uses WMIC.EXE to obtain CPU information

      • cmd.exe (PID: 540)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 9056)
    • Executes as Windows Service

      • WmiApSrv.exe (PID: 6500)
    • Uses WMIC.EXE to obtain BIOS management information

      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 8132)
  • INFO

    • Checks supported languages

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 6816)
      • eDEX-UI.exe (PID: 1596)
      • chcp.com (PID: 7008)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 2216)
      • eDEX-UI.exe (PID: 2084)
      • chcp.com (PID: 5460)
      • chcp.com (PID: 848)
      • chcp.com (PID: 6200)
      • chcp.com (PID: 6544)
    • Creates files or folders in the user directory

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 1596)
    • Reads the computer name

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 6816)
      • eDEX-UI.exe (PID: 1596)
      • eDEX-UI.exe (PID: 2216)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 2084)
    • Create files in a temporary directory

      • eDEX-UI-Windows-x64.exe (PID: 6472)
      • eDEX-UI.exe (PID: 6704)
    • Manual execution by a user

      • eDEX-UI.exe (PID: 6704)
    • Reads product name

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 2216)
    • Reads Environment values

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7072)
      • eDEX-UI.exe (PID: 7080)
      • eDEX-UI.exe (PID: 7052)
      • eDEX-UI.exe (PID: 2216)
    • Drops encrypted VBS script (Microsoft Script Encoder)

      • eDEX-UI.exe (PID: 6704)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • eDEX-UI.exe (PID: 6704)
    • Reads CPU info

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 7052)
    • Process checks computer location settings

      • eDEX-UI.exe (PID: 6704)
      • eDEX-UI.exe (PID: 2216)
    • Changes the display of characters in the console

      • cmd.exe (PID: 6908)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 6088)
      • cmd.exe (PID: 6344)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 5912)
      • cmd.exe (PID: 536)
      • cmd.exe (PID: 6336)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 7016)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 5488)
      • cmd.exe (PID: 540)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 7332)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 7568)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 3560)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 4308)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6308)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 7760)
      • cmd.exe (PID: 3736)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8824)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 2612)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 3620)
      • cmd.exe (PID: 7456)
      • cmd.exe (PID: 8244)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 3700)
      • cmd.exe (PID: 7060)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 5988)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 8272)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 2040)
      • cmd.exe (PID: 7212)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 7408)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 9092)
      • cmd.exe (PID: 9176)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 8640)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 8496)
      • cmd.exe (PID: 9152)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 8908)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 6932)
      • cmd.exe (PID: 4624)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 8564)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8240)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 5556)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7564)
      • cmd.exe (PID: 8732)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 6676)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 776)
      • cmd.exe (PID: 6940)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 5732)
      • cmd.exe (PID: 7428)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 7276)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 1328)
      • cmd.exe (PID: 4504)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 6268)
      • cmd.exe (PID: 6468)
      • cmd.exe (PID: 7404)
      • cmd.exe (PID: 7592)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 9168)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 7816)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 8484)
      • cmd.exe (PID: 8740)
      • cmd.exe (PID: 4992)
      • cmd.exe (PID: 9132)
      • cmd.exe (PID: 7048)
      • cmd.exe (PID: 3224)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 8536)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 4640)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 7576)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 244)
      • cmd.exe (PID: 8008)
      • cmd.exe (PID: 2132)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 1480)
      • cmd.exe (PID: 5208)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 2260)
      • cmd.exe (PID: 6592)
      • cmd.exe (PID: 7676)
      • cmd.exe (PID: 8116)
      • cmd.exe (PID: 7584)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7468)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8864)
      • cmd.exe (PID: 8960)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 9028)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 4160)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 3996)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 4300)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 7308)
      • cmd.exe (PID: 9140)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 6624)
      • cmd.exe (PID: 2136)
      • cmd.exe (PID: 9000)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 6588)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 7528)
      • cmd.exe (PID: 8676)
      • cmd.exe (PID: 9004)
      • cmd.exe (PID: 9204)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 1544)
      • cmd.exe (PID: 6732)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 7220)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 8544)
      • cmd.exe (PID: 8172)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 7304)
    • Checks proxy server information

      • eDEX-UI.exe (PID: 6704)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 6856)
    • The process uses the downloaded file

      • powershell.exe (PID: 6856)
    • Node.js compiler has been detected

      • eDEX-UI.exe (PID: 6704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:02:12 16:15:17+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 30208
InitializedDataSize: 483840
UninitializedDataSize: 16384
EntryPoint: 0x39ed
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.2.8.0
ProductVersionNumber: 2.2.8.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Gabriel 'Squared' SAILLARD
FileDescription: eDEX-UI sci-fi interface
FileVersion: 2.2.8
LegalCopyright: Copyright © 2017-2021 Gabriel 'Squared' SAILLARD <gabriel@saillard.dev> (https://gaby.dev)
ProductName: eDEX-UI
ProductVersion: 2.2.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
1 799
Monitored processes
1 684
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start edex-ui-windows-x64.exe edex-ui.exe no specs edex-ui.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs comppkgsrv.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe no specs edex-ui.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs edex-ui.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs reg.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmiapsrv.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netsh.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs netstat.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs reg.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netstat.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs ipconfig.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs chcp.com no specs chcp.com no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs conhost.exe no specs netstat.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs ipconfig.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs netsh.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs netsh.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs wmic.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs cmd.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs reg.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs chcp.com no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs wmic.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs cmd.exe no specs wmic.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs ipconfig.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs wmic.exe no specs reg.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs edex-ui.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs netstat.exe no specs chcp.com no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs wmic.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs chcp.com no specs chcp.com no specs netstat.exe no specs wmic.exe no specs chcp.com no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
244C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /valueC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
244C:\WINDOWS\system32\cmd.exe /d /s /c "C:\WINDOWS\system32\chcp.com 65001 | C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /value"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
244C:\WINDOWS\system32\cmd.exe /d /s /c "ipconfig /all"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
308\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
308powershell.exe -NoLogo -InputFormat Text -NoExit -ExecutionPolicy Unrestricted -Command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432C:\WINDOWS\system32\cmd.exe /d /s /c "ipconfig /all"C:\Windows\System32\cmd.exeeDEX-UI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432C:\WINDOWS\system32\wbem\wmic.exe path Win32_PerfRawData_Tcpip_NetworkInterface Get name,BytesReceivedPersec,BytesSentPersec,BytesTotalPersec,PacketsOutboundDiscarded,PacketsOutboundErrors,PacketsReceivedDiscarded,PacketsReceivedErrors /valueC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
440\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
114 768
Read events
114 736
Write events
14
Delete events
18

Modification events

(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\eDEX-UI
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:ShortcutName
Value:
eDEX-UI
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayName
Value:
eDEX-UI 2.2.8
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\eDEX-UI\Uninstall eDEX-UI.exe" /currentuser
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\eDEX-UI\Uninstall eDEX-UI.exe" /currentuser /S
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayVersion
Value:
2.2.8
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\eDEX-UI\eDEX-UI.exe,0
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:Publisher
Value:
Gabriel 'Squared' SAILLARD
(PID) Process:(6472) eDEX-UI-Windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\82c1c72c-4db6-57c2-bb24-743f60eb274f
Operation:writeName:NoModify
Value:
1
Executable files
22
Suspicious files
119
Text files
292
Unknown types
61

Dropped files

PID
Process
Filename
Type
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\app-64.7z
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\icudtl.dat
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\LICENSES.chromium.html
MD5:
SHA256:
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Temp\nsqA627.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\LICENSE.electron.txttext
MD5:45574510C534A8195F53B30E3810239E
SHA256:C44607A865E7A6DB05552BAA0EF71F9887D96ACD00D123854B44996BC27C0E33
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\locales\am.pakpgc
MD5:4E7DB89A9F5C07A295DE43B745E5658B
SHA256:4C0B4273DC4103C666FF01ED8B9DB995F68C5C178973465BB25CD5CDF99EF01A
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\locales\cs.pakpgc
MD5:6817671B166242686C18B0D17DC15A80
SHA256:0C554977F587F1910AB077D99B97F5011F5C466F0B6D86DF08F9A4C7C940D99F
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\locales\ar.pakpgc
MD5:70BB1C831327B26E4DD74097F59A55B0
SHA256:776DB47DD91BCE8BC813A54A815BE3E73B6E58E9FE5F24DB7BF0D8C06A240F6A
6472eDEX-UI-Windows-x64.exeC:\Users\admin\AppData\Local\Programs\eDEX-UI\locales\da.pakpgc
MD5:AFDBF3945FBF2CF7FF3787A1761326DB
SHA256:88DA5FAB329C56D1625205CF1A27F508A4797D4129C59D2A966B2628AE4545B9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
65
DNS requests
9
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
204
104.126.37.145:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
2216
eDEX-UI.exe
185.199.108.133:443
raw.githubusercontent.com
FASTLY
US
shared
2216
eDEX-UI.exe
140.82.121.5:443
api.github.com
GITHUB
US
whitelisted
2216
eDEX-UI.exe
1.1.1.1:80
CLOUDFLARENET
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.176
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.140
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared
api.github.com
  • 140.82.121.5
whitelisted
self.events.data.microsoft.com
  • 20.189.173.26
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info