Reads data out of its own binary image Show sources
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00000000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00001ff0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00003fe0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00005fd0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00007fc0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00009fb0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0000bfa0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0000df90, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0000ff80, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00011f70, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00013f60, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00015f50, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00017f40, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00019f30, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0001bf20, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0001df10, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0001ff00, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00021ef0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00023ee0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00025ed0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00027ec0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00029eb0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0002bea0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0002de90, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0002fe80, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00031e70, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00033e60, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00035e50, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00037e40, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00039e30, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0003be20, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0003de10, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0003fe00, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00041df0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00043de0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00045dd0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00047dc0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00049db0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0004bda0, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0004dd90, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0004fd80, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00051d70, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00053d60, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00054000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00055944, length: 0x00010000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00055d50, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00056000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00057d40, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00058000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00059d30, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0005a000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0005bd20, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0005c000, length: 0x00002000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0005c30a, length: 0x0000963a |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x0005e000, length: 0x00004000 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00060000, length: 0x00005944 |
api_process_name | process: 16b493c5a8b014fd3f0eabb66c90f427fee4c84e.exe, pid: 2512, offset: 0x00062000, length: 0x00003944 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f000, length: 0x000001c4 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f00c, length: 0x000001b8 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f024, length: 0x000001a0 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f03c, length: 0x00000188 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f19f, length: 0x00000025 |
api_process_name | process: sets.exe, pid: 2432, offset: 0x0000f1b8, length: 0x0000000c |
Attempts to connect to a dead IP:Port (5 unique times) Show sources
network_host_ip | 216.105.38.13:80 (United States) |
network_host_ip | 162.213.157.36:443 (Canada) |
network_host_ip | 104.27.189.58:443 (unknown) |
network_host_ip | 184.26.44.103:80 (United States) |
network_host_ip | 23.67.250.163:80 (United States) |
Performs some HTTP requests Show sources
network_url | http://downloads.sourceforge.net/project/npppluginmgr/xml/plugins.md5.txt |
network_url | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D |
network_url | http://ocsp.int-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgTUnSbwkleVdmFFlNIuEGjLIA%3D%3D |
network_url | http://crl.globalsign.net/primobject.crl |
Attempts to block SafeBoot use by removing registry keys Show sources
registry_delete | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option |
At least one IP Address, Domain, or File Name was found in a crypto call Show sources
ioc | 0.2.8 |
ioc | 1.1.7.3 |
ioc | http://sourceforge.net/projects/nppactivexplugin/ |
ioc | 1.0.4.2 |
ioc | 6.6.8 |
ioc | http://sourceforge.net/projects/nppactivexplugin/files/bin/ActiveX_Unicode_1_1_7_3.zip/download |
ioc | http://sourceforge.net/projects/nppactivexplugin/files/bin/ActiveX_ANSI_1_1_7_3.zip/download |
ioc | 1.9.24 |
ioc | https://nppscrips.codeplex.com/ |
ioc | v1.0.0.0 |
ioc | 6.4.5 |
ioc | http://www.csscript.net/npp/NppScripts.1.0.0.0.zip |
ioc | cripts.dll |
ioc | readme.txt |
ioc | 1.4.0 |
ioc | http://sites.google.com/site/fstellari/nppplugins |
ioc | http://downloads.sourceforge.net/project/npp-plugins/AutoSave/AutoSave_dll_1v40.zip |
ioc | 1.0.0.0 |
ioc | 1.19 |
ioc | 1.11 |
ioc | 1.12 |
ioc | 1.15 |
ioc | 1.17 |
ioc | 1.18 |
ioc | http://freeweb.siol.net/rmihor/NppCCompletionPlugin.zip |
ioc | lugin.dll |
ioc | ctags.exe |
ioc | 1.2.1 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/ClipboardHelper/ClipboardHelper-v1.0.zip |
ioc | elper.dll |
ioc | http://codealignment.com |
ioc | https://github.com/cpmcgrath/codealignment/releases/download/v12/CodeAlignmentNpp_12_0.zip |
ioc | pp.dll |
ioc | ommon.dll |
ioc | orms.dll |
ioc | 0.8.1 |
ioc | ort-1.0.0.2.zip |
ioc | http://william.famille-blum.org/software/nppcolumnsort/NppColumnSort-1.0.0.2.zip |
ioc | ort.dll |
ioc | http://www.scout-soft.com/combine |
ioc | http://www.scout-soft.com/combine/combine.zip |
ioc | combine.dll |
ioc | 1.5.6 |
ioc | http://sourceforge.net/projects/npp-plugins/files/ComparePlugin/Compare_1_5_5_src.zip/download |
ioc | 1.5.4 |
ioc | 1.5.3 |
ioc | 1.5.2 |
ioc | 1.5.1 |
ioc | http://download.tuxfamily.org/nppplugins/Converter/NppConverter.v3.0.zip |
ioc | onverter.dll |
ioc | xt... |
ioc | 1.1.0.0 |
ioc | http://notepad-plus.sourceforge.net/commun/pluginsBin/ConvertExt_v11RC1.zip |
ioc | xt.dll |
ioc | xt.ini |
ioc | xt.enc |
ioc | xt.lng |
ioc | 1.0.46.0 |
ioc | http://www.csscript.net/npp/ |
ioc | https://csscriptnpp.codeplex.com/ |
ioc | v1.0.46.0 |
ioc | 3.10 |
ioc | 3.11 |
ioc | 6.0. |
ioc | http://downloads.sourceforge.net/project/npp-customize/Customize |
ioc | oolbar.dll |
ioc | 0.0.11.20 |
ioc | http://sourceforge.net/project/downloading.php |
ioc | forge.net/project/npp-plugins/DocMonitor/DocMonitor |
ioc | onitor.v2.2.dll.zip |
ioc | onitor.unicode.dll |
ioc | http://downloads.sourceforge.net/project/npp-plugins/DocMonitor/DocMonitor |
ioc | onitor.ansi.dll |
ioc | http://sourceforge.net/projects/npp-plugins/files/ColorPicker/Color |
ioc | 20v.2.3/ColorPicker_230_dll.zip/download |
ioc | icker.dll |
ioc | 0.2.5 |
ioc | https://github.com/dail8859/doxyit |
ioc | https://github.com/dail8859/DoxyIt/releases/download/v0.2.5/DoxyIt.zip |
ioc | t.dll |
ioc | https://github.com/editorconfig/editorconfig-notepad-plus-plus |
ioc | http://downloads.sourceforge.net/project/editorconfig/EditorConfig-Notepad |
ioc | 0.1.3/Unicode/NppEditorConfig.zip |
ioc | onfig.dll |
ioc | 0.1.3/Ansi/NppEditorConfig.zip |
ioc | http://www.eibericht.nl |
ioc | http://eibericht.nl/eibericht16.zip |
ioc | eibericht.dll |
ioc | i-bericht.ini |
ioc | 1.0.2 |
ioc | http://emmet.io |
ioc | https://github.com/emmetio/npp |
ioc | http://download.emmet.io/npp/emmet-np |
ioc | 0.1.1 |
ioc | http://github.com/ppv/NPPFSIPlugin/tree/master/Source/Plugin |
ioc | 0.1.0.0 |
ioc | 0.1.1.0 |
ioc | http://github.com/downloads/ppv/NPPFSIPlugin/NPPFSIPlugin.zip |
ioc | http://downloads.sourceforge.net/project/npp-plugins/FallingBricks/FallingBricks |
ioc | dll.zip |
ioc | ricks.dll |
ioc | change.log |
ioc | license.txt |
ioc | 1.0.3.0 |
ioc | http://www.brotherstone.co.uk/npp/FTP_Synchronise/FTP_synchronize_amend.zip |
ioc | synchronize.dll |
ioc | http://downloads.sourceforge.net/project/npp-plugins/FTP_synchronize/FTP_synchronize |
ioc | 20v0.9.6.1/FTP_synchronize_0_9_6_1_dll.zip |
ioc | 1.2.0.0 |
ioc | 2.0.0.0 |
ioc | http://sourceforge.net/projects/npp-plugins/files/ |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/FunctionList_2_0_UNI_dll.zip |
ioc | ules.xml |
ioc | ist.dll |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/FunctionList_1_2_dll.zip |
ioc | 0.2.0.37 |
ioc | http://www.genapps.net |
ioc | http://sourceforge.net/projects/gedcomlexer/ |
ioc | http://sourceforge.net/projects/gedcomlexer/files/GedcomLexer-0.2 |
ioc | ua.xml |
ioc | ua.dll |
ioc | http://golang.org/doc/install |
ioc | https://github.com/nsf/gocode |
ioc | https://github.com/tike/GOnpp |
ioc | 28.03.2014 |
ioc | v1.2.0.0 |
ioc | n19.02.2014 |
ioc | v1.1.0.0 |
ioc | n24.01.2014 |
ioc | http://sourceforge.net/projects/gonpp/files/GOnpp_1.2_UNI.zip/download |
ioc | npp.dll |
ioc | 1.0.0 |
ioc | ugs.com |
ioc | https://grepbugs.com/plugins |
ioc | https://github.com/foospidy/GrepBugsPluginNotepadPlusPlus |
ioc | .index.php |
ioc | http://f0dder.dcmembers.com/nppplugs/npp_plugins.zip |
ioc | guidguard.dll |
ioc | 0.9.5.0 |
ioc | https://sourceforge.net/projects/npp-plugins/files/ |
ioc | v0.9.3 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/Hex |
ioc | 20v0.9.5/HexEditor_0_9_5_UNI_dll.zip |
ioc | ditor.dll |
ioc | 20v0.9. |
ioc | nicode.zip |
ioc | mage.dll |
ioc | lus.dll |
ioc | ag.dll |
ioc | 0.7.1 |
ioc | https://code.google.com/p/indentbyfold/ |
ioc | https://indentbyfold.googlecode.com/files/IndentByFold-071.zip |
ioc | old.dll |
ioc | e.pdf |
ioc | http://www.jslint.com/lint.html |
ioc | https://sourceforge.net/projects/jslintnpp/ |
ioc | www.jshint.com |
ioc | http://www.sunjw.us/jstoolnpp |
ioc | https://github.com/sunjw/jstoolnpp |
ioc | http://sourceforge.net/projects/jsminnpp/files/Uni/JSToolNPP.1.16.10.uni.zip/download |
ioc | http://sourceforge.net/projects/jsminnpp/files/Asc/JSToolNPP.1.16.10.asc.zip/download |
ioc | 1.6.1 |
ioc | https://sites.google.com/site/fstellari/nppplugins/LanguageHelp_dll_1v61.zip |
ioc | elp.dll |
ioc | https://sourceforge.net/projects/lexamples |
ioc | http://sourceforge.net/projects/lexamples/files/v1.0.0/lexamples_1_0_0.zip/download |
ioc | lexamples.dll |
ioc | lexamples.xml |
ioc | 1.6.0.0 |
ioc | https://sourceforge.net/projects/locationnav/ |
ioc | https://sourceforge.net/projects/locationnav/files/ |
ioc | 0.4.3 |
ioc | 0.4.5.1 |
ioc | 0.4.7.1 |
ioc | 0.4.7.2 |
ioc | 0.4.7.3 |
ioc | 0.4.7.4 |
ioc | 0.4.7.5 |
ioc | 0.4.7.6 |
ioc | 0.4.7.7 |
ioc | http://sourceforge.net/projects/locationnav/files/LocationNavigate_v0.4.7.7.zip/download |
ioc | avigate.dll |
ioc | release.zip |
ioc | stats.cfg |
ioc | 0.0.3.0 |
ioc | 0.0.5.5 |
ioc | http://www.semelinanno.com/downloads/anmxnpp/anmXNpp_Page.html |
ioc | http://semelinanno.com/downloads/mathpad/ver0050/MathPad_v0050.zip |
ioc | http://semelinanno.com/downloads/mathpad/ver0055/MathPad_v0055.zip |
ioc | mathpad.dll |
ioc | http://www.semelinanno.com/downloads/anmxnpp/ver0030/anmXNpp_v0030.zip |
ioc | 1.1.0 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/MultiClipboard/MultiClipboard |
ioc | lipboard.dll |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/MultiClipboard_1_4_1_dll.zip |
ioc | eadme.txt |
ioc | 1.0.0.3 |
ioc | https://sourceforge.net/projects/nppmusicplayer |
ioc | https://github.com/gallettube/MusicPlayer |
ioc | v1.0.0.3 |
ioc | v1.0.0.2 |
ioc | v1.0.0.1 |
ioc | http://downloads.sourceforge.net/project/nppmusicplayer/MusicPlayer.zip |
ioc | layer.dll |
ioc | ceforge.net/projects/locationnav/files/ |
ioc | 0.1.0 |
ioc | 0.1.2 |
ioc | 0.1.3 |
ioc | http://sourceforge.net/projects/locationnav/files/NewFileBrowser_v0.1.3.zip/download |
ioc | rowser.dll |
ioc | http://sourceforge.net/projects/locationnav/files/NewFileBrowserA_v0.1.3.zip/download |
ioc | 1.5.0 |
ioc | https://github.com/lygstate/NotepadStarter/archive/2.0.0.0.zip |
ioc | https://github.com/lygstate/NotepadStarter/releases/download/2.0.0.0/NotepadStarter-2.0.0.0.zip |
ioc | tarter.exe |
ioc | nstall.bat |
ioc | eplacer.bat |
ioc | ninstall.bat |
ioc | readme.md |
ioc | request-admin.bat |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/NppAutoIndent_1_2_dll.zip |
ioc | ndent.dll |
ioc | http://www.cerberus-design.de/nppcrypt/nppcryptv1010.zip |
ioc | rypt.dll |
ioc | readme.v1010.txt |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/NppDocShare_0_1_src.zip |
ioc | 0.5.3 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/ |
ioc | saved.txt |
ioc | http://sourceforge.net/projects/npp-plugins/files/NppExec/NppExec |
ioc | 20v0.5.3/NppExec_053_dll_Unicode.zip/download |
ioc | xec.dll |
ioc | 1.0.2a |
ioc | 0.6.5 |
ioc | http://downloads.sourceforge.net/project/nppftp/NppFTP_0.26.3.zip |
ioc | libssh.txt |
ioc | http://downloads.sourceforge.net/project/nppftp/NppFTP_0.26.zip |
ioc | 0.26 |
ioc | 3.1.0 |
ioc | 1.2.2/NppJumpList.1.2.2.bin.zip |
ioc | 0.7.5 |
ioc | http://sourceforge.net/projects/nppmenusearch/ |
ioc | http://www2.brotherstone.co.uk/npp/NppMenuSearch075.zip |
ioc | earch.dll |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/NppDocShare_0_1_dll.zip |
ioc | hare.dll |
ioc | http://sourceforge.net/projects/notepad-plus/forums/forum/482781/topic/5333716 |
ioc | http://dl.dropbox.com/u/163495/NppPlates.zip |
ioc | lates.dll |
ioc | 1.3.4 |
ioc | orge.net/project/npp-plugins/Oberon2Lexer/Oberon2Lexer |
ioc | exer.v0.3.zip |
ioc | 0.3.1 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/Oberon2Lexer/Oberon2Lexer |
ioc | 200.3.1/Oberon2Lexer.v0.3.1.zip |
ioc | exer.dll |
ioc | exer.xml |
ioc | 2.3.2 |
ioc | orge.net |
ioc | http://downloads.sourceforge.net/project/npp-plugins/Obide/Obide |
ioc | 202.3.2/Obide.v.2.3.2.zip |
ioc | bide.ini |
ioc | election.dll |
ioc | 2.0.0.1 |
ioc | http://www.brotherstone.co.uk/npp/perforce/NppPerforcePlugin_Source.zip |
ioc | http://www.brotherstone.co.uk/npp/perforce/NppPerforcePlugin_Unicode.zip |
ioc | http://www.brotherstone.co.uk/npp/perforce/NppPerforcePlugin_Ansi.zip |
ioc | nsi.dll |
ioc | 1.4.1 |
ioc | https://github.com/StanDog/npp-phpautocompletion |
ioc | n08.03.2014 |
ioc | v1.2.3 |
ioc | n28.02.2014 |
ioc | v1.2.2 |
ioc | n27.02.2014 |
ioc | v1.2.1 |
ioc | n26.02.2014 |
ioc | i.a. |
ioc | n05.12.2013 |
ioc | n01.04.2013 |
ioc | v1.0.1 |
ioc | https://github.com/Stan |
ioc | http://www.brotherstone.co.uk/npp/changemarker/NppPlugin_ChangeMarker_Unicode_bin.zip |
ioc | argin.dll |
ioc | argin.xml |
ioc | http://www.brotherstone.co.uk/npp/changemarker/NppPlugin_ChangeMarker_Ansi_bin.zip |
ioc | 0.3.0.0 |
ioc | http://fstellari.googlepages.com/PluginUpdate_dll_0v30.zip |
ioc | http://www.architectshack.com/PoorMansTSqlFormatter.ashx |
ioc | https://github.com/TaoK/PoorMansTSqlFormatter |
ioc | http://www.architects |
ioc | http://download.tuxfamily.org/nppplugins/Pork2Sausage/Pork2Sausage.bin.1.0.zip |
ioc | ausage.ini |
ioc | e.txt |
ioc | ausage.dll |
ioc | http://poshcode.org/notepad |
ioc | exer.1.0.src.zip |
ioc | exer.1.0.unicode.zip |
ioc | exers.dll |
ioc | elp.txt |
ioc | exers.xml |
ioc | exer.1.0.ansi.zip |
ioc | 1.2.1.0 |
ioc | http://fossil.2of4.net/npp_preview/ |
ioc | http://fossil.2of4.net/npp_preview/zip/Preview_plugin_src.zip |
ioc | https://github.com/mpcabd/PyNPP/releases/download/v1.2/PyNPP.dll.zip |
ioc | http://code.google.com/p/kereds-notepad-plus-plus-plugins |
ioc | http://kereds-notepad-plus-plus-plugins.googlecode.com/files/Python |
ioc | ndent.zip |
ioc | 1.0.6 |
ioc | notepad.open |
ioc | filename.txt |
ioc | editor.appendText |
ioc | http://npppythonscript.sourceforge.net |
ioc | http://github.com/davegb3/PythonScript |
ioc | editor.pymlreplace |
ioc | editor.getCharacterPointer |
ioc | notepad.getPluginVersion |
ioc | http://downloads.sourceforge.net/project/npppythonscript/Python |
ioc | file.php |
ioc | http://sourceforge.net/projects/quickopenplugin/ |
ioc | http://downloads.sourceforge.net/project/quickopenplugin/QuickOpenPlugin |
ioc | 1.2.zip |
ioc | 0.0.2.1 |
ioc | 0.0.2.2 |
ioc | http://sourceforge.net/tracker/ |
ioc | ext.conf.ini |
ioc | ext.default.ini |
ioc | ext.ini |
ioc | ext.conf.default.ini |
ioc | http://downloads.sourceforge.net/project/quicktext/QuickText/QuickText |
ioc | 200.2.1/QuickText.v0.2.1.zip |
ioc | ext.v0.2.1 |
ioc | http://poiru.github.com/rainlexer |
ioc | http://nppregexhelper.sourceforge.net/ |
ioc | https://github.com/larryb82/npp-regexhelper |
ioc | https://sites.google.com/site/fstellari/nppplugins/RunMe_dll_1v36.zip |
ioc | e.dll |
ioc | https://sourceforge.net/projects/nppsaveasadmin/ |
ioc | https://sourceforge.net/p/nppsaveasadmin/code/ |
ioc | http://downloads.sourceforge.net/project/nppsaveasadmin/NppSaveAsAdmin_1.0.0.3.zip |
ioc | dmin.dll |
ioc | 201.12/SearchInFiles_1_12_dll.zip |
ioc | iles.dll |
ioc | http://www.dreaminpixels.net/wp-content/plugins/download-monitor/download.php |
ioc | ad.dll |
ioc | http://downloads.sourceforge.net/project/npp-plugins/SecurePad/SecurePad |
ioc | ad.v1.0.bin.zip |
ioc | http://download.tuxfamily.org/nppplugins/SelectNLaunch/SelectNLaunch.bin.v1.0.zip |
ioc | aunch.dll |
ioc | 1.4.2 |
ioc | http://mfoster.com/npp/SessionMgr.html |
ioc | http://mfoster.com/npp/download.html |
ioc | https://sourceforge.net/p/notepad-plus/discussion/482781/thread/dea823d0/ |
ioc | v1.4.2 |
ioc | http://downloads.sourceforge.net/project/npp-plugins/SimpleScript/SimpleScript |
ioc | 20v1.13/SimpleScript_1_13_dll.zip |
ioc | cript.ini |
ioc | cript.dll |
ioc | http://www.snip2code.com/Static/Downloads |
ioc | https://github.com/cghersi/snip2codeNET |
ioc | http://www.snip2code.com/Downloads/S2CNotepadppPlugin.zip |
ioc | ode.dll |
ioc | log4net.dll |
ioc | son.dll |
ioc | vc.dll |
ioc | http://downloads.sourceforge.net/project/snippetplus/SnippetPlus_V1.4_Release.zip |
ioc | lus.xml |
ioc | e.html |
ioc | hangelog.txt |
ioc | moke.css |
ioc | rown.css |
ioc | 1.2.0 |
ioc | http://www.fesevur.com/nppsnippets |
ioc | http://code.google.com/p/nppsnippets/ |
ioc | 3.7.15.1 |
ioc | solutionhub.dll |
ioc | 2.178 |
ioc | http://www.incrediblejunior.com/npp_plugins/ |
ioc | http://www.incrediblejunior.com/npp_plugins/downloads/r1/solutionhub_ui.zip |
ioc | ui.dll |
ioc | 0.7.3 |
ioc | http://sourceforge.net/projects/sourcecookifier/ |
ioc | n0.7.2 |
ioc | n0.7.1 |
ioc | http://downloads.sourceforge.net/project/sourcecookifier/0.7.3/SourceCookifier.v0.7.3.bin.zip |
ioc | ookifier.dll |
ioc | olicy.bat |
ioc | ookifier.languages.model.xml |
ioc | file1.php |
ioc | 0.2.0.1 |
ioc | 0.2.1.0 |
ioc | http://sourceforge.net/projects/npp-plugins/files/SpeechPlugin/SpeechPlugin_0_2_1_src.zip/download |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/SpeechPlugin_0_2_1_dll.zip |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/SpeechPlugin_0_2_dll.zip |
ioc | 1.3.1.0 |
ioc | 1.3.3.0 |
ioc | http://aspell.net/win32. |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/SpellChecker_1_3_3_UNI_dll.zip |
ioc | hecker.dll |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/SpellChecker_1_3_1_dll.zip |
ioc | http://www.scout-soft.com/sql/ |
ioc | http://www.scout-soft.com/ |
ioc | http://f0dder.dcmembers.com/nppplugs.index.php |
ioc | switcher.dll |
ioc | http://kereds-notepad-plus-plus-plugins.googlecode.com/files/TabIndentSpaceAlign.zip |
ioc | lign.dll |
ioc | 1.0.3 |
ioc | 7.0.2 |
ioc | http://downloads.sourceforge.net/project/tagsview/TagsView |
ioc | 03beta.zip |
ioc | ctags.opt |
ioc | iew.txt |
ioc | iew.dll |
ioc | 1.1.1 |
ioc | http://textfx.no-ip.com/textfx/ |
ioc | http://downloads.sourceforge.net/project/npp-plugins/TextFX/TextFX |
ioc | 20v0.26/TextFX.v0.26.unicode.bin.zip |
ioc | 20v0.25/NPPTextFX.v0.25.bin.zip |
ioc | http://sourceforge.net/projects/npptfs |
ioc | http://downloads.sourceforge.net/project/npptfs/NppTFS.zip |
ioc | http://code.google.com/p/npp-tidy2/ |
ioc | https://github.com/davegb3/NppTidy2 |
ioc | http://npp-tidy2.googlecode.com/files/Tidy2_0.2.zip |
ioc | idy2.dll |
ioc | http://tortoisesvn.tigris.org/ |
ioc | 2.186 |
ioc | 2.195 |
ioc | http://www.incrediblejunior.com/npp_plugins/downloads/tsvn_r195.zip |
ioc | svn.dll |
ioc | help.txt |
ioc | tsvn.config |
ioc | 3.1.1.0 |
ioc | https://sourceforge.net/projects/npptranslate/ |
ioc | https://sourceforge.net/p/npptranslate/code/HEAD/tree/nppTranslateCS/ |
ioc | http://sourceforge.net/projects/npptranslate/files/bin/Translate_3.1.1.0.zip/download |
ioc | ranslate.dll |
ioc | 1.0.2_NotepadPPplugin |
ioc | http://downloads.sourceforge.net/project/universalindent/uigui/UniversalIndentGUI_1.0.2/UniversalIndentGUI_1.0.2_NotepadPPplugin.zip |
ioc | ore4.dll |
ioc | ui4.dll |
ioc | cript4.dll |
ioc | 1.0.2_N |
ioc | https://sourceforge.net/projects/nppverilog/ |
ioc | https://sourceforge.net/p/nppverilog/code/ci/master/tree/ |
ioc | v1.2.0 |
ioc | http://sourceforge.net/projects/nppverilog/files/nppVerilog |
ioc | 20v1.2.1/nppVerilog_v1.2.1.zip/download |
ioc | erilog.dll |
ioc | onfig.txt |
ioc | https://sourceforge.net/projects/nppvhdl/ |
ioc | https://sourceforge.net/p/nppvhdl/code/ci/master/tree/ |
ioc | http://sourceforge.net/projects/nppvhdl/files/NppVHDL |
ioc | 20v1.0.0/nppVHDL_v1.0.0.zip/download |
ioc | 0.4.0.109 |
ioc | 0.3.6.868 |
ioc | 0.3.6.838 |
ioc | http://www.visimulator.com/public/p/pm/visimulator_0.4.0.1093.zip |
ioc | 0.4.0.1093.dll |
ioc | visimulator.dll |
ioc | 2.0.3 |
ioc | https://wakatime.com/ |
ioc | https://github.com/wakatime/notepadpp-wakatime |
ioc | n1.1.0 |
ioc | n1.0.0 |
ioc | https://github.com/wakatime/notepadpp-wakatime/releases/download/2.0.3/notepadpp-wakatime-2.0.3.zip |
ioc | http://downloads.sourceforge.net/project/npp-plugins/WebEdit/WebEdit |
ioc | dit.v2.1.zip |
ioc | dit.ini |
ioc | dit.dll |
ioc | 1.1.2.0 |
ioc | 1.2.2.0 |
ioc | http://sourceforge.net/projects/npp-plugins/files/WindowManager/WindowManager_1_2_2_src.zip/download |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/WindowManager_1_2_2_UNI_dll.zip |
ioc | anager.dll |
ioc | http://downloads.sourceforge.net/sourceforge/npp-plugins/WindowManager_1_1_2_dll.zip |
ioc | 4.1.0.16 |
ioc | http://sourceforge.net/projects/npp-plugins/files/XML |
ioc | 202.4.4 |
ioc | nicode.zip/download |
ioc | 2.0.0.513 |
ioc | 2.1.0 |
ioc | 2.1.1.548 |
ioc | 2.2.0.560 |
ioc | 2.3.0.583 |
ioc | 2.3.1.639 |
ioc | 2.3.1.670 |
ioc | 2.3.1.671 |
ioc | 2.3.1.685 |
ioc | 2.3.1.697 |
ioc | 2.3.1.764 |
ioc | 2.3.1.805 |
ioc | 2.3.2.908 |
ioc | 2.4.1 |
ioc | 2.4.2 |
ioc | 2.4.3 |
ioc | 2.4.4 |
ioc | 2.4.5 |
ioc | 2.4.6 |
ioc | 2.4.7 |
ioc | 2.4.8 |
ioc | 2.9.2 |
ioc | 1.1.28 |
ioc | 1.2.20 |
ioc | 1.2.6 |
ioc | 1.14 |
ioc | 1.0.1j |
ioc | 202.4.8 |
ioc | libiconv-2.dll |
ioc | libwinpthread-1.dll |
ioc | libxml2-2.dll |
ioc | libxslt-1.dll |
ioc | zlib1.dll |
ioc | ools.dll |
ioc | libcurl.dll |
ioc | 2.10 |
ioc | https://code.google.com/p/xpatherizernpp/ |
ioc | http://xpatherizernpp.googlecode.com/files/XPatherizerNPP-2.10-Source.rar |
ioc | ython.dll |
ioc | 1.1.3 |
ioc | https://github.com/StanDog/npp-zoomdisabler |
ioc | 21.06.2015 |
ioc | v1.1.3 |
ioc | n19.02.2015 |
ioc | v1.1.2 |
ioc | n30.03.2014 |
ioc | v1.1.1 |
ioc | n29.03.2014 |
ioc | n28.03.2014 |
ioc | https://github.com/StanDog/npp-zoomdisabler/raw/master/RELEASES/zoomdisabler_1.1.3.zip |
ioc | zoomdisabler.dll |
ioc | disabler.ini |
ioc | mscoree.dll |
ioc | kernel32.dll |
ioc | 32.dll |
ioc | onverter.pdb |
ioc | 4.01//EN |
ioc | http://www.w3.org/TR/1999/REC-html401-19991224/strict.dtd |
ioc | u.j8h |
ioc | 1.2.8 |
ioc | http://www.winimage.com/zLibDll |
ioc | anager.pdb |
ioc | 3.3g3t3 |
Steals private information from local Internet browsers Show sources
file_read | C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@downloads.sourceforge[1].txt |
Attempts to modify proxy settings
Creates RWX memory Show sources
injection_rwx_memory | 0x00000040, NtProtectVirtualMemory |
Drops a binary and executes it Show sources
file_dropped | C:\Program Files (x86)\amd\sets.exe |
Possible date expiration check, exits too soon after checking local time Show sources
api_process_name | attrib.exe, PID 1452 |
A process attempted to delay the analysis task. Show sources
api_process_name | bitsadmin.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds |
Creates a hidden or system file Show sources
file_write | C:\Users\user\AppData\Local\Temp\ytmp |
file_write | C:\Users\user\AppData\Roaming\update\BITBD98.tmp |