Source: powershell.exe, 00000001.00000002.2010532480.0000000002B40000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: wab.exe, 00000005.00000002.2869316085.0000000020591000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: wab.exe, 00000005.00000002.2869316085.0000000020591000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: wab.exe, 00000005.00000002.2869316085.00000000205CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000005.00000002.2869316085.00000000205E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://legodimo.co.za |
Source: wab.exe, 00000005.00000002.2869316085.00000000205CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000005.00000002.2869316085.00000000205E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://mail.legodimo.co.za |
Source: hnTW5HdWvY.exe, hnTW5HdWvY.exe.1.dr | String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: hnTW5HdWvY.exe, hnTW5HdWvY.exe.1.dr | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: powershell.exe, 00000001.00000002.2013851591.0000000005A6A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000001.00000002.2011308617.0000000004B56000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2015644677.00000000071A6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000001.00000002.2011308617.0000000004A01000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000005.00000002.2869316085.0000000020541000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000001.00000002.2011308617.0000000004B56000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2015644677.00000000071A6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2015644677.0000000007210000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000001.00000002.2011308617.0000000004A01000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore6lBqq |
Source: wab.exe, 00000005.00000002.2869316085.0000000020541000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org |
Source: wab.exe, 00000005.00000002.2869316085.0000000020541000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/ |
Source: wab.exe, 00000005.00000002.2869316085.0000000020541000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/t |
Source: powershell.exe, 00000001.00000002.2013851591.0000000005A6A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000001.00000002.2013851591.0000000005A6A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000001.00000002.2013851591.0000000005A6A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000001.00000002.2011308617.0000000004B56000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2015644677.00000000071A6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.2015644677.0000000007210000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: wab.exe, 00000005.00000002.2857526156.0000000000B58000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lifeartfertility.co.za/ |
Source: wab.exe, 00000005.00000002.2857936435.0000000000E90000.00000004.00001000.00020000.00000000.sdmp, wab.exe, 00000005.00000002.2857526156.0000000000B58000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lifeartfertility.co.za/dKatzZJXqh143.bin |
Source: wab.exe, 00000005.00000002.2857526156.0000000000B58000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lifeartfertility.co.za/dKatzZJXqh143.bind |
Source: wab.exe, 00000005.00000002.2857526156.0000000000B58000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lifeartfertility.co.za/o |
Source: powershell.exe, 00000001.00000002.2013851591.0000000005A6A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Code function: 0_2_004047E2 | 0_2_004047E2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_0489F4F8 | 1_2_0489F4F8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_0489EDB0 | 1_2_0489EDB0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A7B7B0 | 5_2_00A7B7B0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A74AC0 | 5_2_00A74AC0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A7EB60 | 5_2_00A7EB60 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A73EA8 | 5_2_00A73EA8 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A7EF10 | 5_2_00A7EF10 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A741F0 | 5_2_00A741F0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233C2794 | 5_2_233C2794 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233C39B0 | 5_2_233C39B0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233C2CE0 | 5_2_233C2CE0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233C2CD3 | 5_2_233C2CD3 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233C39DB | 5_2_233C39DB |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D6228 | 5_2_233D6228 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233DB259 | 5_2_233DB259 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D51E0 | 5_2_233D51E0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D30A0 | 5_2_233D30A0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D2379 | 5_2_233D2379 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233DE3E8 | 5_2_233DE3E8 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D72E0 | 5_2_233D72E0 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_233D590F | 5_2_233D590F |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: fontext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: fms.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: dlnashext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Section loaded: wpdshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_0489AA6A pushad ; ret | 1_2_0489AA71 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_048910E7 push eax; retf 0070h | 1_2_04891122 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_04891127 push eax; retf 0070h | 1_2_04891132 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_04891137 push eax; retf 0070h | 1_2_04891142 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CB00A9 push ss; ret | 1_2_08CB00B2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CB49D6 push edi; iretd | 1_2_08CB49D5 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CBE9EA push 6D4A5B23h; retf | 1_2_08CBE9F1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CB498E push edi; iretd | 1_2_08CB49D5 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CB0134 push ebx; ret | 1_2_08CB013E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CB3F48 pushad ; ret | 1_2_08CB3F49 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 1_2_08CBFF07 push 67AC2B90h; iretd | 1_2_08CBFF13 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_00A70C95 push edi; ret | 5_2_00A70CC2 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_042200A9 push ss; ret | 5_2_042200B2 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_04220134 push ebx; ret | 5_2_0422013E |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_0422498E push edi; iretd | 5_2_042249D5 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_0422E9EA push 6D4A5B23h; retf | 5_2_0422E9F1 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_042249D6 push edi; iretd | 5_2_042249D5 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_0422FF07 push 67AC2B90h; iretd | 5_2_0422FF13 |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Code function: 5_2_04223F48 pushad ; ret | 5_2_04223F49 |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7212 | Thread sleep time: -3689348814741908s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -27670116110564310s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7696 | Thread sleep count: 2947 > 30 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599889s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7696 | Thread sleep count: 6868 > 30 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599781s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599671s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599562s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599437s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599325s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599218s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -599108s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598985s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598871s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598734s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598608s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598473s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -598325s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99875s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99765s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99656s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99547s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99437s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99328s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99218s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99109s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -99000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98890s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98781s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98672s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98562s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98453s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98344s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98234s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98125s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -98015s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97905s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97785s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97656s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97547s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97422s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97312s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97203s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -97093s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96984s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96875s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96765s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96656s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96547s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96422s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96312s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96203s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -96093s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -95984s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -95875s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe TID: 7692 | Thread sleep time: -95763s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599889 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599671 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599562 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599325 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 599108 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598985 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598871 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598734 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598608 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598473 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 598325 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99765 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99656 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99547 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99437 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99328 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99218 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99109 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 99000 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98890 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98781 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98672 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98562 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98453 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98344 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98234 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98125 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 98015 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97905 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97785 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97656 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97547 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97422 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97312 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97203 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 97093 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96984 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96875 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96765 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96656 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96547 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96422 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96312 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96203 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 96093 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 95984 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 95875 | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Thread delayed: delay time: 95763 | Jump to behavior |
Source: C:\Users\user\Desktop\hnTW5HdWvY.exe | Code function: 0_2_100010D3 GetModuleFileNameA,GlobalAlloc,CharPrevA,GlobalFree,GetTempFileNameA,CopyFileA,CreateFileA,CreateFileMappingA,MapViewOfFile,UnmapViewOfFile,CloseHandle,CloseHandle,CloseHandle,lstrcatA,lstrlenA,GlobalAlloc,FindWindowExA,FindWindowExA,FindWindowExA,lstrcmpiA,DeleteFileA,GlobalAlloc,GlobalLock,GetVersionExA,InitializeSecurityDescriptor,SetSecurityDescriptorDacl,CreatePipe,CreatePipe,CreatePipe,GetStartupInfoA,CreateProcessA,lstrcpyA,GetTickCount,PeekNamedPipe,GetTickCount,ReadFile,lstrlenA,lstrlenA,lstrlenA,lstrcpynA,lstrlenA,GlobalSize,GlobalUnlock,GlobalReAlloc,GlobalLock,lstrcatA,GlobalSize,lstrlenA,lstrcpyA,CharNextA,GetTickCount,TerminateProcess,lstrcpyA,Sleep,WaitForSingleObject,GetExitCodeProcess,PeekNamedPipe,lstrcpyA,lstrcpyA,wsprintfA,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,DeleteFileA,GlobalFree,GlobalFree,GlobalUnlock,GlobalFree, | 0_2_100010D3 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Program Files (x86)\Windows Mail\wab.exe VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Windows Mail\wab.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |