Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003243000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003234000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031F9000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003207000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000314B000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.com |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003215000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003243000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003234000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031F9000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003207000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000314B000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000318E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003140000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003081000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/ |
Source: 109__Purchase_Order.exe, 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/q |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003243000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003234000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003163000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031F9000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003207000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://reallyfreegeoip.org |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003081000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003251000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://scratchdreams.tk |
Source: 109__Purchase_Order.exe |
String found in binary or memory: http://tempuri.org/DataSet1.xsd |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003334000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://us2.smtp.mailhostbox.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.carterandcone.coml |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers? |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designersG |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fonts.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.goodfont.co.kr |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sajatypeworks.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1692997195.0000000005AF0000.00000004.00000020.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sakkal.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sandoll.co.kr |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.tiro.com |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.typography.netD |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.urwpp.deDPlease |
Source: 109__Purchase_Order.exe, 00000000.00000002.1693165904.0000000007262000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.zhongyicts.com.cn |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003243000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003234000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031F9000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003207000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000314B000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000318E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org |
Source: 109__Purchase_Order.exe, 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000314B000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/102.129.152.231 |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003243000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003234000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031F9000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003207000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.000000000318E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.00000000031DE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/102.129.152.231$ |
Source: 109__Purchase_Order.exe, 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003251000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003081000.00000004.00000800.00020000.00000000.sdmp, 109__Purchase_Order.exe, 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://scratchdreams.tk |
Source: 109__Purchase_Order.exe, 00000002.00000002.4075654635.0000000003251000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://scratchdreams.tk/_send_.php?TS |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects executables with potential process hoocking Author: ditekSHen |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7304, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7304, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7532, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7532, type: MEMORYSTR |
Matched rule: Detects Snake Keylogger Author: ditekSHen |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.109__Purchase_Order.exe.442b100.9.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.109__Purchase_Order.exe.444b920.7.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 2.2.109__Purchase_Order.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.109__Purchase_Order.exe.444b920.7.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.109__Purchase_Order.exe.442b100.9.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000002.00000002.4074742141.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1691234350.000000000435E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7304, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7304, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7532, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 109__Purchase_Order.exe PID: 7532, type: MEMORYSTR |
Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, ofMc7kSjLqFQ721OW8.cs |
High entropy of concatenated method names: 'kq1X59TDiD', 'qT9XqZBD2t', 'uYsXdqUql7', 'deJXTDhgBP', 'WCtX96obJj', 'R3JXK0LZG1', 'wMhXHf1hBx', 'gaRXj23cY9', 'xUZXnIvGxw', 'rHJXW594AT' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, HOW2huMWuH24JAKIss.cs |
High entropy of concatenated method names: 'r9ZF1a7g7W', 'auXF5286Mj', 'X5VFqxmeSt', 'SqXFd0Utof', 'W6EFTl8nev', 'AAsF9Rjvep', 'kdlFKIlVtm', 'IYVFHdWnfY', 'nerFjUsNGW', 'BrOFncMRT0' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, jcEPgTbuGk9a0DVG02.cs |
High entropy of concatenated method names: 'BOcXYiC9yG', 'uplXuEX9D2', 'aJWXfO63j1', 'AhDXhJXqol', 'BLUXtftJUc', 'lMtXMQ8Jso', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, evek6BLcvke2fGAw2F.cs |
High entropy of concatenated method names: 'yMt4Jwqx4h', 'cpk4sUmUEa', 'Trp4YSIyAn', 'cZM4ue7rC8', 'QX94hMs9Yl', 'i6n4MG19Rj', 'VGt4P3qRwa', 'lwH4Bv6WUa', 'rJM4r4yfOG', 'eyH4pM2jV1' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, Gut9Ewn4ddg6joA4vi.cs |
High entropy of concatenated method names: 'kkmK5e6m72', 'dI8Kd8m14s', 'TcQK9MLiSA', 'TXY9i7lASE', 'HGv9zh7XrD', 'amrKoxVnup', 'lnhKmvyLUM', 'F7SKat9JAJ', 'VRxKF4H5EI', 'O7xKCGMM9d' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, CQO8IbYU17tGjjxd23.cs |
High entropy of concatenated method names: 'JopLm5AhXV', 'PAMLFLRSbE', 'T9RLCL821S', 'EUKL5HIMLr', 'eN6LqPltD0', 'DisLT70MDM', 'nPKL9lbg1o', 'iw3XNRhUIf', 'wwmX65lrFK', 'Dr0XZHFkEB' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, fnI6us3IgPBqmng04s.cs |
High entropy of concatenated method names: 'mK09gfnDei', 'biA9yX4v0H', 'uh19kHoYg7', 'kMk9GEAqrY', 'uhe9Sti858', 'LCD98W5IdP', 'GXW9sLsi61', 'hiZ9wb6vI8', 'gp4F0p3i6hXbjGK7WNl', 'cZjWoi3OUHwoLByrQ7n' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, c7G1s7QBOOZM36BDQn.cs |
High entropy of concatenated method names: 'A5cqtjFuvs', 'MeyqeyLVYw', 'A5dqbaTUbc', 'yAmqISDhZv', 'sL5qAA5hpK', 'wmiqOr0EVP', 'masqN1wmdU', 'cLnq6fgI7n', 'WoqqZyVamO', 'aVlqisR6BB' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, IbXF8jBrWJjZpHVyg7N.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'luJQtAbrIF', 'QpeQeagT3s', 'xraQbMnGQJ', 'fyGQIY3fkO', 'TguQAEoJQt', 'nbTQOvie8Y', 'y5jQN5dpn5' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, kBnWKD6s4FcdQnOKPq.cs |
High entropy of concatenated method names: 'suAmKFr5ZH', 'tZQmHP2d0A', 'WLKmntGeg4', 'VVQmWM6Y2B', 'aZdmD9DQsv', 'TnHm2iou8o', 'KrOagMktLA5erNHZ9j', 'fWNCjY7rR60BgoIA8q', 'gDNmmZZx5K', 'LABmFTEiSo' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, Bs4Lti9JmpwTlEvneK.cs |
High entropy of concatenated method names: 'fivdGKYb4s', 'bqZdS3IofQ', 'vKYdJhZi3f', 'n9odsJ5eRi', 'P6tdDSZkQw', 'L4nd2tlMfr', 'MiFdEp1PHZ', 'YXNdXAsOCD', 'YLndLb8WNs', 'FQTdQXGZUq' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, x42rRpoStLLHSoccQX.cs |
High entropy of concatenated method names: 'H9WEnyNGhw', 'ih5EWcmA17', 'ToString', 'K9SE5K8CrZ', 'qKBEqJQTYJ', 'h6OEdHup9J', 'psSETFf6Rd', 'AnME9Dm1aM', 'HK5EK51tGp', 'PRuEHNZgJC' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, yxdkC1VeQpQ4MXEEFJ.cs |
High entropy of concatenated method names: 'cpfk801If', 'EbdGj9HZ7', 'bN8S09euc', 'rYD8rWKbf', 'fJUsWjt8P', 'FPIw4SsxS', 'JD2rlOKPcQh2kfrgUh', 'Yr8gPZRIE5Pjgr8vwV', 'V7QX5qIsV', 'dNlQqOJ1N' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, OrOWP3BG8kwAgXb9pIp.cs |
High entropy of concatenated method names: 'cYrLyVQSnC', 'HK3L0FsUVr', 'PS4Lkm9RLw', 'U03LG8glBu', 'dHELldMv3D', 'VVDLSDbhsj', 'a0wL8VliG3', 'fLCLJN8WUx', 'yOCLsy76YZ', 'q2WLwksSsD' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, fe8puFlDcqURUIC0vF.cs |
High entropy of concatenated method names: 'pAsKyxXMQo', 'X3cK0JHe4r', 'HgQKkT08lX', 'H9WKGGtu5H', 'NUjKldvobk', 'WfvKSIfCM8', 'zSZK8aTF9f', 'froKJotanD', 'K9tKsYiNYD', 'WoyKwgllUo' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, shsLPlzoLrkYCdBPmM.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'pt6L4W7iMw', 'glfLD7GMnL', 'ViuL2P6NZE', 'IkULEUso3e', 'S2RLX4CWRO', 'TnlLLi7m1L', 'V95LQ7asO1' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, gqS9nWwXBEY5Fr49ds.cs |
High entropy of concatenated method names: 'YrY91Ko4QJ', 'z8r9qXnuHL', 'uxc9TVCLBZ', 'Erc9KOAG2O', 'XKr9HjwQlw', 'KG8TA5Hyi4', 'q2ETOEO6c2', 'bKATNJSkmk', 'MRgT6jYBb7', 'VGQTZCsnAE' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, sGYLIBRP2UYPvkC8iu.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'WHraZ9EUJY', 'n64aiZob5Z', 'D9Aaz4cvov', 'UTjFoPytLF', 'RjBFmtCN41', 'zfbFap0Q4e', 'zxgFFDOt0W', 'EfQfxsJcb6OWPNPihSq' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, Y1x70KpXwX06bg0SJN.cs |
High entropy of concatenated method names: 'ToString', 'uvD2pBdY6O', 'lrX2u3PfO4', 'TJP2fdWpyj', 'yv82hCfc9h', 'nJq2M0QZK6', 'pe523OwpAy', 'dY22P8YM4d', 'Ghm2BvZIBo', 'so72RoxdHy' |
Source: 0.2.109__Purchase_Order.exe.7740000.12.raw.unpack, S2gI0tJTis4pOlOImq.cs |
High entropy of concatenated method names: 'Dispose', 'GHnmZdayLT', 'MJBauUv4OB', 'i9D77uqY2K', 'M4smi9nM1t', 'YftmzwlvxG', 'ProcessDialogKey', 'zNEaobqWC0', 'xndamBaBPa', 'NHdaaTudBH' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, ofMc7kSjLqFQ721OW8.cs |
High entropy of concatenated method names: 'kq1X59TDiD', 'qT9XqZBD2t', 'uYsXdqUql7', 'deJXTDhgBP', 'WCtX96obJj', 'R3JXK0LZG1', 'wMhXHf1hBx', 'gaRXj23cY9', 'xUZXnIvGxw', 'rHJXW594AT' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, HOW2huMWuH24JAKIss.cs |
High entropy of concatenated method names: 'r9ZF1a7g7W', 'auXF5286Mj', 'X5VFqxmeSt', 'SqXFd0Utof', 'W6EFTl8nev', 'AAsF9Rjvep', 'kdlFKIlVtm', 'IYVFHdWnfY', 'nerFjUsNGW', 'BrOFncMRT0' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, jcEPgTbuGk9a0DVG02.cs |
High entropy of concatenated method names: 'BOcXYiC9yG', 'uplXuEX9D2', 'aJWXfO63j1', 'AhDXhJXqol', 'BLUXtftJUc', 'lMtXMQ8Jso', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, evek6BLcvke2fGAw2F.cs |
High entropy of concatenated method names: 'yMt4Jwqx4h', 'cpk4sUmUEa', 'Trp4YSIyAn', 'cZM4ue7rC8', 'QX94hMs9Yl', 'i6n4MG19Rj', 'VGt4P3qRwa', 'lwH4Bv6WUa', 'rJM4r4yfOG', 'eyH4pM2jV1' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, Gut9Ewn4ddg6joA4vi.cs |
High entropy of concatenated method names: 'kkmK5e6m72', 'dI8Kd8m14s', 'TcQK9MLiSA', 'TXY9i7lASE', 'HGv9zh7XrD', 'amrKoxVnup', 'lnhKmvyLUM', 'F7SKat9JAJ', 'VRxKF4H5EI', 'O7xKCGMM9d' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, CQO8IbYU17tGjjxd23.cs |
High entropy of concatenated method names: 'JopLm5AhXV', 'PAMLFLRSbE', 'T9RLCL821S', 'EUKL5HIMLr', 'eN6LqPltD0', 'DisLT70MDM', 'nPKL9lbg1o', 'iw3XNRhUIf', 'wwmX65lrFK', 'Dr0XZHFkEB' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, fnI6us3IgPBqmng04s.cs |
High entropy of concatenated method names: 'mK09gfnDei', 'biA9yX4v0H', 'uh19kHoYg7', 'kMk9GEAqrY', 'uhe9Sti858', 'LCD98W5IdP', 'GXW9sLsi61', 'hiZ9wb6vI8', 'gp4F0p3i6hXbjGK7WNl', 'cZjWoi3OUHwoLByrQ7n' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, c7G1s7QBOOZM36BDQn.cs |
High entropy of concatenated method names: 'A5cqtjFuvs', 'MeyqeyLVYw', 'A5dqbaTUbc', 'yAmqISDhZv', 'sL5qAA5hpK', 'wmiqOr0EVP', 'masqN1wmdU', 'cLnq6fgI7n', 'WoqqZyVamO', 'aVlqisR6BB' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, IbXF8jBrWJjZpHVyg7N.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'luJQtAbrIF', 'QpeQeagT3s', 'xraQbMnGQJ', 'fyGQIY3fkO', 'TguQAEoJQt', 'nbTQOvie8Y', 'y5jQN5dpn5' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, kBnWKD6s4FcdQnOKPq.cs |
High entropy of concatenated method names: 'suAmKFr5ZH', 'tZQmHP2d0A', 'WLKmntGeg4', 'VVQmWM6Y2B', 'aZdmD9DQsv', 'TnHm2iou8o', 'KrOagMktLA5erNHZ9j', 'fWNCjY7rR60BgoIA8q', 'gDNmmZZx5K', 'LABmFTEiSo' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, Bs4Lti9JmpwTlEvneK.cs |
High entropy of concatenated method names: 'fivdGKYb4s', 'bqZdS3IofQ', 'vKYdJhZi3f', 'n9odsJ5eRi', 'P6tdDSZkQw', 'L4nd2tlMfr', 'MiFdEp1PHZ', 'YXNdXAsOCD', 'YLndLb8WNs', 'FQTdQXGZUq' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, x42rRpoStLLHSoccQX.cs |
High entropy of concatenated method names: 'H9WEnyNGhw', 'ih5EWcmA17', 'ToString', 'K9SE5K8CrZ', 'qKBEqJQTYJ', 'h6OEdHup9J', 'psSETFf6Rd', 'AnME9Dm1aM', 'HK5EK51tGp', 'PRuEHNZgJC' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, yxdkC1VeQpQ4MXEEFJ.cs |
High entropy of concatenated method names: 'cpfk801If', 'EbdGj9HZ7', 'bN8S09euc', 'rYD8rWKbf', 'fJUsWjt8P', 'FPIw4SsxS', 'JD2rlOKPcQh2kfrgUh', 'Yr8gPZRIE5Pjgr8vwV', 'V7QX5qIsV', 'dNlQqOJ1N' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, OrOWP3BG8kwAgXb9pIp.cs |
High entropy of concatenated method names: 'cYrLyVQSnC', 'HK3L0FsUVr', 'PS4Lkm9RLw', 'U03LG8glBu', 'dHELldMv3D', 'VVDLSDbhsj', 'a0wL8VliG3', 'fLCLJN8WUx', 'yOCLsy76YZ', 'q2WLwksSsD' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, fe8puFlDcqURUIC0vF.cs |
High entropy of concatenated method names: 'pAsKyxXMQo', 'X3cK0JHe4r', 'HgQKkT08lX', 'H9WKGGtu5H', 'NUjKldvobk', 'WfvKSIfCM8', 'zSZK8aTF9f', 'froKJotanD', 'K9tKsYiNYD', 'WoyKwgllUo' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, shsLPlzoLrkYCdBPmM.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'pt6L4W7iMw', 'glfLD7GMnL', 'ViuL2P6NZE', 'IkULEUso3e', 'S2RLX4CWRO', 'TnlLLi7m1L', 'V95LQ7asO1' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, gqS9nWwXBEY5Fr49ds.cs |
High entropy of concatenated method names: 'YrY91Ko4QJ', 'z8r9qXnuHL', 'uxc9TVCLBZ', 'Erc9KOAG2O', 'XKr9HjwQlw', 'KG8TA5Hyi4', 'q2ETOEO6c2', 'bKATNJSkmk', 'MRgT6jYBb7', 'VGQTZCsnAE' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, sGYLIBRP2UYPvkC8iu.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'WHraZ9EUJY', 'n64aiZob5Z', 'D9Aaz4cvov', 'UTjFoPytLF', 'RjBFmtCN41', 'zfbFap0Q4e', 'zxgFFDOt0W', 'EfQfxsJcb6OWPNPihSq' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, Y1x70KpXwX06bg0SJN.cs |
High entropy of concatenated method names: 'ToString', 'uvD2pBdY6O', 'lrX2u3PfO4', 'TJP2fdWpyj', 'yv82hCfc9h', 'nJq2M0QZK6', 'pe523OwpAy', 'dY22P8YM4d', 'Ghm2BvZIBo', 'so72RoxdHy' |
Source: 0.2.109__Purchase_Order.exe.4496410.8.raw.unpack, S2gI0tJTis4pOlOImq.cs |
High entropy of concatenated method names: 'Dispose', 'GHnmZdayLT', 'MJBauUv4OB', 'i9D77uqY2K', 'M4smi9nM1t', 'YftmzwlvxG', 'ProcessDialogKey', 'zNEaobqWC0', 'xndamBaBPa', 'NHdaaTudBH' |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599547 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599217 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599109 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599000 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598891 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598531 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598422 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598312 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598203 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598094 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597406 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597297 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597187 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597078 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596969 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596859 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596750 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596391 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596169 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596062 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595953 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595835 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595734 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595623 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595391 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595266 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595156 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595047 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594938 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594813 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594688 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594578 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594469 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7324 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -24903104499507879s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7636 |
Thread sleep count: 8494 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7636 |
Thread sleep count: 1357 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599217s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -599000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598891s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598641s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598422s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -598094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597641s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597516s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -597078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596969s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596641s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596516s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596391s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596169s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -596062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595835s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595623s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595516s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595391s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -595047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -594938s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -594813s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -594688s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -594578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe TID: 7632 |
Thread sleep time: -594469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599875 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599547 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599217 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599109 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 599000 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598891 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598531 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598422 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598312 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598203 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 598094 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597766 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597406 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597297 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597187 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 597078 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596969 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596859 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596750 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596641 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596391 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596169 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 596062 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595953 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595835 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595734 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595623 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595516 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595391 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595266 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595156 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 595047 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594938 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594813 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594688 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594578 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Thread delayed: delay time: 594469 |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Users\user\Desktop\109__Purchase_Order.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Users\user\Desktop\109__Purchase_Order.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\109__Purchase_Order.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |