Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.9 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92. |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.2 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.24 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.2002902278.000001EE5936B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.2002902278.000001EE59431000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248. |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.3 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36 |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/ |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/D |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Do |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Dow |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Down |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downl |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downlo |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloa |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Download |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/ |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/c |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/co |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/con |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/conf |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/confi |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config. |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.e |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3981000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.ex |
Source: mshta.exe, 00000005.00000002.2917406886.000001F0BD89B000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907162331.000001F0BD8F3000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe |
Source: powershell.exe |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe$global:? |
Source: mshta.exe, 00000005.00000002.2917281391.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2916094280.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe& |
Source: mshta.exe, 00000005.00000003.2907320112.000001F0BD89A000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000002.2917406886.000001F0BD89B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe&r |
Source: mshta.exe, 00000005.00000002.2917755583.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2912251391.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2915981491.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907162331.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe... |
Source: mshta.exe, 00000005.00000002.2917755583.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2912251391.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2915981491.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907162331.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe...d |
Source: mshta.exe, 00000005.00000002.2917755583.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2912251391.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2915981491.000001F0BD90C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe0 |
Source: mshta.exe, 00000005.00000002.2917406886.000001F0BD8B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907320112.000001F0BD8B5000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exe5t |
Source: mshta.exe, 00000005.00000002.2917214384.000001F0BD840000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2916060842.000001F0BD8FB000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000002.2917709575.000001F0BD8FD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2912251391.000001F0BD8F3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907162331.000001F0BD8F3000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeC: |
Source: mshta.exe, 00000005.00000002.2917281391.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2916094280.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeE |
Source: mshta.exe, 00000005.00000003.2907320112.000001F0BD89A000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000002.2917406886.000001F0BD89B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeFr |
Source: mshta.exe, 00000005.00000002.2917149646.000001F0BD820000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeH |
Source: mshta.exe, 00000005.00000002.2917281391.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2916094280.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeJ |
Source: mshta.exe, 00000005.00000002.2918270849.000001F0BDA10000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeLE_STRING7 |
Source: mshta.exe, 00000005.00000002.2917281391.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2916094280.000001F0BD866000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeMB |
Source: mshta.exe, 00000005.00000002.2917214384.000001F0BD840000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exef |
Source: mshta.exe, 00000005.00000003.2913495827.000001F8C0955000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exehttp://91.92.248.36/Downloads/config.exe |
Source: mshta.exe, 00000005.00000002.2917214384.000001F0BD840000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://91.92.248.36/Downloads/config.exeq |
Source: powershell.exe, 00000012.00000002.2189816681.0000025D724E1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.mic |
Source: powershell.exe, 00000012.00000002.2189816681.0000025D724E1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.micft.cMicRosof |
Source: powershell.exe, 00000002.00000002.2022569662.0000013FBBBC9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.micros |
Source: svchost.exe, 00000006.00000002.3222077994.0000023264200000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.ver) |
Source: powershell.exe, 00000002.00000002.2021942530.0000013FBBB68000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crlft.com/pki/crl/pMicRooCerAut_201crl0Z |
Source: powershell.exe, 00000002.00000002.2021942530.0000013FBBB68000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://csoft.com/pki/crls/MicRooCerAut_23.crl0Z |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/ |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567 |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg |
Source: qmgr.db.6.dr |
String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe |
Source: edb.log.6.dr |
String found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20 |
Source: powershell.exe, 00000002.00000002.2021942530.0000013FBBB68000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://osoft.com/pki/ceooCerAut_2010-068 |
Source: powershell.exe, 00000012.00000002.2070802265.0000025D00229000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000012.00000002.2070802265.0000025D01598000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3751000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.2002902278.000001EE58F47000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000007.00000002.2811535315.000002349BD49000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2406897956.000002BB85451000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000012.00000002.2070802265.0000025D00001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000012.00000002.2070802265.0000025D00229000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000012.00000002.2070802265.0000025D01598000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000009.00000002.2406897956.000002BB8585D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://sensor.fun |
Source: powershell.exe, 00000009.00000002.2406897956.000002BB8585D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://sensor.fun/tiago.exep |
Source: powershell.exe, 00000009.00000002.2406897956.000002BB8567B000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://urler.site |
Source: powershell.exe, 00000009.00000002.2406897956.000002BB8567B000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://urler.site/document.jpg |
Source: powershell.exe, 00000012.00000002.2189816681.0000025D72488000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://wwoft.com/pkiops/cWinProPCA2011_20.crt0 |
Source: powershell.exe, 00000007.00000002.2892973214.00000234B3E97000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.microsoft. |
Source: powershell.exe, 00000012.00000002.2189816681.0000025D72488000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://wwwft.com/pkiops/crProPCA2011_2011-l0a |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3751000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.2002902278.000001EE58F0A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.2002902278.000001EE58F1E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000007.00000002.2811535315.000002349BCD5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000007.00000002.2811535315.000002349BD12000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2406897956.000002BB85451000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000012.00000002.2070802265.0000025D00001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: edb.log.6.dr |
String found in binary or memory: https://g.live.com/odclientsettings/Prod/C: |
Source: svchost.exe, 00000006.00000003.2011226930.0000023263F30000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.6.dr, edb.log.6.dr |
String found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C: |
Source: powershell.exe, 00000002.00000002.2010897376.0000013FA3C3C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2010897376.0000013FA40A1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000007.00000002.2811535315.000002349C264000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: mshta.exe, 00000005.00000002.2917533960.000001F0BD8D4000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000005.00000003.2907162331.000001F0BD8D2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://login.live.com |
Source: qmgr.db.6.dr |
String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe/C: |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: mshtml.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: msiso.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: srpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: ieframe.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: msimtf.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: dataexchange.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: imgutil.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: jscript9.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\mshta.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: qmgr.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: bitsperf.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: firewallapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: esent.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: fwbase.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: flightsettings.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: netprofm.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: npmproxy.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: bitsigd.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: upnp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ssdpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: appxdeploymentclient.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: wsmauto.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: wsmsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: dsrole.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: pcwum.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: msv1_0.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ntlmshared.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: cryptdll.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: webio.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: rmclient.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: usermgrcli.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: execmodelclient.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: execmodelproxy.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: vssapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: vsstrace.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: samlib.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: es.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: bitsproxy.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\svchost.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasman.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rtutils.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winhttp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: twinui.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: execmodelproxy.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mrmcorer.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositorycore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47mrm.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.ui.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windowmanagementapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: inputhost.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: ieframe.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: linkinfo.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntshrui.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cscapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: taskflowdataengine.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cdp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: umpdc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dsreg.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: bthavctpsvc.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: powrprof.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: wpprecorderum.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: umpdc.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\svchost.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: ieframe.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: netapi32.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: winhttp.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wkscli.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: mlang.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Windows\System32\fodhelper.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: linkinfo.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntshrui.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cscapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: taskflowdataengine.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cdp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: umpdc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dsreg.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|