Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\Crypto.Cipher._AES.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_ctypes.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_hashlib.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_socket.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_ssl.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\09isgp VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\09isgp VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32api.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_sqlite3.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\tmpo8tal6\gen_py\__init__.py VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\tmpo8tal6\gen_py\dicts.dat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32com.shell.shell.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32console.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32file.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32gui.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\win32process.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\pyexpat.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\psutil._psutil_windows.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\PIL._imaging.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.advanced.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.config.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.tools.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.browsers_scan.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.misc.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.regkey.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.ie.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.firefox.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.optimizejars.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.chrome.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.browsers_scan.opera.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.windows_scripts.hosts.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.windows_scripts.installed_softwares.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.windows_scripts.security_products_state.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.windows_scripts.autostarts.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.disk.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memscan.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.yarapy.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.MemWorker.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.Process.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.BaseProcess.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.utils.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.WinProcess.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.structures.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.WinStructures.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.Address.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.memorpy.Locator.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.windows_scripts.signatures.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.eof.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.amcache.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.registry_file.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.volume_shadow_copy.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.registry_live.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.registry_tracks.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.forensic_scripts.registry.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\eof.process.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\embedded\yara\tehtris_enc.yar VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\embedded\yara\tehtris_enc.yar VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\cryptography-1.7.2-py2.7.egg-info\entry_points.txt VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\cryptography-1.7.2-py2.7.egg-info\entry_points.txt VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\cryptography.hazmat.bindings._constant_time.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\_cffi_backend.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\unicodedata.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI70442\cryptography.hazmat.bindings._openssl.pyd VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dwm.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dwm.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0515~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\winlogon.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\winlogon.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\lsass.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\lsass.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\fontdrvhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\fontdrvhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package00~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dllhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dllhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\wbem\WmiPrvSE.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\wbem\WmiPrvSE.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\spoolsv.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\spoolsv.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\conhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\conhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\backgroundTaskHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\backgroundTaskHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0510~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\ApplicationFrameHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\ApplicationFrameHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0515~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\conhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\conhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\sihost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\sihost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\ctfmon.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dasHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dasHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0511~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\explorer.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\svchost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0516~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0512~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dllhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\dllhost.exe VolumeInformation |
Source: C:\Users\user\Desktop\tehtris_offline_forensic_2.6.0.0.exe | Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |