Source: rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C6B000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: rNNA.exe, 00000006.00000002.2907319846.0000000001376000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2920697212.0000000006219000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q |
Source: rNNA.exe, 00000006.00000002.2919997760.0000000006BB2000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2920697212.00000000061F2000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/cPanelIncCertificationAuthority.crl0 |
Source: rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://mail.pbjv.net |
Source: rNNA.exe, 00000006.00000002.2919997760.0000000006BB2000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2907319846.0000000001376000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2920697212.00000000061F2000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2920697212.0000000006219000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C6B000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.comodoca.com0 |
Source: rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pbjv.net |
Source: rNNA.exe, 00000000.00000002.1689121052.0000000003024000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 00000007.00000002.1718509352.0000000002774000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.carterandcone.coml |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers? |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designersG |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fonts.com |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.goodfont.co.kr |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sajatypeworks.com |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sakkal.com |
Source: rNNA.exe, 00000000.00000002.1698474694.00000000059F0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.sakkal.coms |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sandoll.co.kr |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.tiro.com |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.typography.netD |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.urwpp.deDPlease |
Source: rNNA.exe, 00000000.00000002.1698525882.0000000007072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.zhongyicts.com.cn |
Source: rNNA.exe, 00000000.00000002.1693403396.000000000412E000.00000004.00000800.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2906608211.000000000042C000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: rNNA.exe, 00000006.00000002.2919997760.0000000006BB2000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2907319846.0000000001406000.00000004.00000020.00020000.00000000.sdmp, rNNA.exe, 00000006.00000002.2910329972.0000000003246000.00000004.00000800.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2920697212.00000000061F2000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2907874313.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, wZnyuP.exe, 0000000C.00000002.2910473470.0000000002A66000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://sectigo.com/CPS0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_02F1480C |
0_2_02F1480C |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_02F1787F |
0_2_02F1787F |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_07630040 |
0_2_07630040 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_076301E8 |
0_2_076301E8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_07660720 |
0_2_07660720 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_076649C0 |
0_2_076649C0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_076649B0 |
0_2_076649B0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_07664988 |
0_2_07664988 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_092D4640 |
0_2_092D4640 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_092D6168 |
0_2_092D6168 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_092DC280 |
0_2_092DC280 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_094709F0 |
0_2_094709F0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_09477348 |
0_2_09477348 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_09477358 |
0_2_09477358 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_094752E8 |
0_2_094752E8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_0947570F |
0_2_0947570F |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_09476F20 |
0_2_09476F20 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_09475720 |
0_2_09475720 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_0947AE30 |
0_2_0947AE30 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 0_2_09474EB0 |
0_2_09474EB0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014D41C8 |
6_2_014D41C8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014D9BF8 |
6_2_014D9BF8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014D4A98 |
6_2_014D4A98 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014DCF48 |
6_2_014DCF48 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014D3E80 |
6_2_014D3E80 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C2EF0 |
6_2_066C2EF0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C56D8 |
6_2_066C56D8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C3F48 |
6_2_066C3F48 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066CDD20 |
6_2_066CDD20 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C05B8 |
6_2_066C05B8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C8B98 |
6_2_066C8B98 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C3648 |
6_2_066C3648 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066C4FF8 |
6_2_066C4FF8 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_066CBFD0 |
6_2_066CBFD0 |
Source: C:\Users\user\Desktop\rNNA.exe |
Code function: 6_2_014D9BF7 |
6_2_014D9BF7 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_00CB480C |
7_2_00CB480C |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_00CB7880 |
7_2_00CB7880 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068B4640 |
7_2_068B4640 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068B4630 |
7_2_068B4630 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068BC513 |
7_2_068BC513 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068B6168 |
7_2_068B6168 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068D0720 |
7_2_068D0720 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068D49B0 |
7_2_068D49B0 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_068D49C0 |
7_2_068D49C0 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D94EB0 |
7_2_06D94EB0 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D9570F |
7_2_06D9570F |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D96F20 |
7_2_06D96F20 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D95720 |
7_2_06D95720 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D952E8 |
7_2_06D952E8 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D9A230 |
7_2_06D9A230 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D97358 |
7_2_06D97358 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 7_2_06D97348 |
7_2_06D97348 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00EC4A98 |
12_2_00EC4A98 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00EC9B38 |
12_2_00EC9B38 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00EC3E80 |
12_2_00EC3E80 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00ECCE80 |
12_2_00ECCE80 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00ECC06F |
12_2_00ECC06F |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_00EC41C8 |
12_2_00EC41C8 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_0581BD10 |
12_2_0581BD10 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_0581DD10 |
12_2_0581DD10 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05818B8A |
12_2_05818B8A |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05819AE8 |
12_2_05819AE8 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05814FF8 |
12_2_05814FF8 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05813F48 |
12_2_05813F48 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_058156D8 |
12_2_058156D8 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05812EF0 |
12_2_05812EF0 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05813637 |
12_2_05813637 |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Code function: 12_2_05810040 |
12_2_05810040 |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: mswsock.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: schannel.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Section loaded: msasn1.dll |
|
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, TFU7OEOCenJdNgHXXR.cs |
High entropy of concatenated method names: 'e9U10rpNqt', 'piV1pNc1sQ', 'slt1Zyg675', 'xdm18ncu9m', 'o1T1g96IUW', 'wO81PDMH4r', 'v701tgBc8C', 'XCg17KI5Eg', 'M0k1SAg51a', 'kwC1bIuOZk' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, oSJuv0s4i9E6iOJbFZ.cs |
High entropy of concatenated method names: 'Vbd4GfC2D5', 'MSt49nHAPl', 'uPP43ncY1F', 'fxJ4v43vCp', 'IX04yZbN5p', 'D6g4MF5B7w', 'Qli4AajjSV', 'haF4JJ5rCp', 'wbV4BZXO67', 'zIX4Ip0UD9' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, CFkMRMnOrncPkNcVM7.cs |
High entropy of concatenated method names: 'Dispose', 'b3LaBIfqsn', 'UaQmi8LfSS', 'kGRRRud94L', 'm15aIicPoW', 'AJTazuvGUx', 'ProcessDialogKey', 'moIm5ATcGM', 'GXema4WnDr', 'uR9mmQ4K7P' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, gLFgNTpDvFFQ0Quoh76.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'WKp2GZFgEk', 'IQe29uIMdn', 'MQS23ZM0Le', 'lrf2v3uksq', 'MGo2yqJEij', 'Igl2MpBWkT', 'iG72A0i14t' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, J79WTJpmftIhoTV9FiW.cs |
High entropy of concatenated method names: 'swud0dHfGW', 'PPwdpULMNF', 't6TdZo1syt', 'IdDd8VjWT4', 'wR6dgufVYF', 'DSidPLjU39', 'fG7dt0o6dV', 'LCVd7DOXwe', 't6RdSRBh4M', 'T2jdb7RV4M' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, Q8tcVrfcpwla0nUGDY.cs |
High entropy of concatenated method names: 'ToString', 'hOFwLGxYBa', 'Db5wiX1siu', 's06wDjrxQ0', 'bcOwW7vwID', 'Y1DwFXKyRS', 'mjGwj3vJ3I', 'L3FwhmjRyP', 'lIowN8cuAe', 'k1Fwk8hGUP' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, ioAaKJeTMiDIDcxpTF.cs |
High entropy of concatenated method names: 'H0ta1EA5SG', 'PIkaoPYFmR', 'JYGaq6AZ56', 'vD3aYKhk5v', 'jmmalCs5Kq', 'i4yawHdLao', 'NDvXDaMWjMAgtjFgE2', 'cyfoJ9Uc13e5YsK45W', 'zAmaa8CmGq', 'LEtaOhhqew' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, dCKYUrjXOXcIT9y3vI.cs |
High entropy of concatenated method names: 'MmffT3XATF', 'bhcfiNdEPA', 'KUlfD2JnYL', 'L52fW5j5EV', 'iwpfGBMyDq', 'FY2fFiV4G7', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, MrT2AfiN81blrM7ofh.cs |
High entropy of concatenated method names: 'Fil68wRVKh', 'uV96PgsEAu', 'wGW67Fa14W', 'iLi6SF1QQU', 'R3D6lF5cYk', 'YyD6wFTLn3', 'r5s6cAOTPE', 'uT26fMxvgs', 'Axv6dcNtid', 'EWW62x0JWN' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, V3prQuAj3Ol4OExEGv.cs |
High entropy of concatenated method names: 'VPKfngqLZD', 'ctvf4lSqmn', 't6Kf6sTWFR', 'eN6frFr9NH', 'DqvfsFFBEL', 'g7Of1PbsFF', 'nL5foJpBCl', 'ArufXnEolv', 'WFnfqPavWT', 'fMJfYK3LF9' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, ywb8dSUlRHcITytTBP.cs |
High entropy of concatenated method names: 'v1Trghfk51', 'zWCrt9RyXT', 'qRn6DM2aH8', 'rF36WuVWFf', 'Yfi6FbSECt', 'j4d6jpQxwE', 'tLn6hNNvuC', 'duX6NaTxcD', 'eLs6kfqbPN', 'wQq6KvsqVR' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, L0scfAZViKfKXE4Hg6.cs |
High entropy of concatenated method names: 'GoUsHUjcLE', 'l4Bs4ciWeA', 'A1lsrYmU5u', 'J6ls12hdkG', 'pH4soEeAmi', 'r6Vryqm8uA', 'MWhrMRmkfC', 'X3UrA9E4wb', 'adyrJkqPpD', 'BJ8rB91Q1I' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, JUWfI2zWuid0Q7O0ZT.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'FvCdVBYBY3', 'MMcdlKhE7Q', 'R7bdwcBg53', 'grDdcV5P3D', 'Iokdfwtdsv', 'vV0ddqQBBj', 'DiNd2bJVBk' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, lw2l7RhtXX8UM9HjGF.cs |
High entropy of concatenated method names: 'qwxOHLyv85', 'xo4On4KijT', 'tGtO4MU2X3', 'UhqO64N7nm', 'e9FOrnTEMX', 'mdbOsDJZkN', 'ie2O1uJP7v', 'RAKOoD8Zdj', 'IiROXmk3Un', 'mu1Oqlj2iW' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, LaiKv15nLAvK9HiqXE.cs |
High entropy of concatenated method names: 'KJodaK2pB4', 'OUgdOLHLjB', 'FcTdQEkgb6', 'GxDdnTyJVg', 'Uhdd4kL5ud', 'sKvdrq8S3n', 'sCpdsG6tT0', 'H82fAm2Mn1', 'OFOfJ69G0i', 'LQvfBe4xgp' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, UhXjfdrLjoQJACNZXp.cs |
High entropy of concatenated method names: 'k8AV7MDF0Z', 'gIOVS8JeGK', 'mYtVT1H95B', 'StuViTsro7', 'grVVW8cgVJ', 'Tt2VFSFurG', 'M7AVhqmqlC', 'oCPVNN60k4', 'QoBVK4Aqu3', 'smoVL7l3c3' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, yfLSmUJL7Z9ql1Bg8U.cs |
High entropy of concatenated method names: 'QTj1n7xIKB', 'npi16AYrGb', 'xAs1sceBq5', 'tUisIqWQAK', 'MgVszLQQd6', 'Q0D15V1Y1m', 'Dkd1a1vQGX', 'owu1mkSP8e', 'o081O2TZHc', 'yrZ1QecFU0' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, U3WXjgkIoYPtq8pCPP.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'uWXmBfuuuN', 'yxUmIZRFLx', 'Ms5mzKCgrU', 'n4BO5S4upY', 'q0oOakFsbK', 'YUMOmyKRPt', 'wonOOOvjan', 'ipKWIs4qRCkvW7cqTIw' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, jCHoQs4nofL44OacKx.cs |
High entropy of concatenated method names: 'D9JZv46aD', 'rvC8A2YCm', 'iPMPwl4E6', 'tC1trdkLt', 'y67SMuhcv', 'MyJbUeo1v', 'WnpxdWkCYxRA8Cqd8F', 'tORjKHPvhoxhZEc91h', 'mref77Ptw', 'vVZ2ymoiE' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, NlMwpiGmyTNGuLogXe.cs |
High entropy of concatenated method names: 'tOacqJh5GA', 'FVacYsgqrj', 'ToString', 'xlQcnZlWp7', 'eMdc4fbHbx', 'a3Zc6JGUdo', 'grYcrMfBZK', 'sOLcsRU0UH', 'o3vc1emvxq', 'v8JcoHUN0F' |
Source: 0.2.rNNA.exe.96a0000.16.raw.unpack, RTRqeKChxrikX2k2eR.cs |
High entropy of concatenated method names: 'GiNVSGKySP8VUaHonO9', 'zN47tQKTVDeCUjajadx', 'eSEsfXAcdM', 'qjLsdhHFta', 'sAJs27ejYo', 'BPuhBiKwWQiXDZXhk26', 'EII46jKvsnjp64ihgik' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, TFU7OEOCenJdNgHXXR.cs |
High entropy of concatenated method names: 'e9U10rpNqt', 'piV1pNc1sQ', 'slt1Zyg675', 'xdm18ncu9m', 'o1T1g96IUW', 'wO81PDMH4r', 'v701tgBc8C', 'XCg17KI5Eg', 'M0k1SAg51a', 'kwC1bIuOZk' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, oSJuv0s4i9E6iOJbFZ.cs |
High entropy of concatenated method names: 'Vbd4GfC2D5', 'MSt49nHAPl', 'uPP43ncY1F', 'fxJ4v43vCp', 'IX04yZbN5p', 'D6g4MF5B7w', 'Qli4AajjSV', 'haF4JJ5rCp', 'wbV4BZXO67', 'zIX4Ip0UD9' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, CFkMRMnOrncPkNcVM7.cs |
High entropy of concatenated method names: 'Dispose', 'b3LaBIfqsn', 'UaQmi8LfSS', 'kGRRRud94L', 'm15aIicPoW', 'AJTazuvGUx', 'ProcessDialogKey', 'moIm5ATcGM', 'GXema4WnDr', 'uR9mmQ4K7P' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, gLFgNTpDvFFQ0Quoh76.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'WKp2GZFgEk', 'IQe29uIMdn', 'MQS23ZM0Le', 'lrf2v3uksq', 'MGo2yqJEij', 'Igl2MpBWkT', 'iG72A0i14t' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, J79WTJpmftIhoTV9FiW.cs |
High entropy of concatenated method names: 'swud0dHfGW', 'PPwdpULMNF', 't6TdZo1syt', 'IdDd8VjWT4', 'wR6dgufVYF', 'DSidPLjU39', 'fG7dt0o6dV', 'LCVd7DOXwe', 't6RdSRBh4M', 'T2jdb7RV4M' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, Q8tcVrfcpwla0nUGDY.cs |
High entropy of concatenated method names: 'ToString', 'hOFwLGxYBa', 'Db5wiX1siu', 's06wDjrxQ0', 'bcOwW7vwID', 'Y1DwFXKyRS', 'mjGwj3vJ3I', 'L3FwhmjRyP', 'lIowN8cuAe', 'k1Fwk8hGUP' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, ioAaKJeTMiDIDcxpTF.cs |
High entropy of concatenated method names: 'H0ta1EA5SG', 'PIkaoPYFmR', 'JYGaq6AZ56', 'vD3aYKhk5v', 'jmmalCs5Kq', 'i4yawHdLao', 'NDvXDaMWjMAgtjFgE2', 'cyfoJ9Uc13e5YsK45W', 'zAmaa8CmGq', 'LEtaOhhqew' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, dCKYUrjXOXcIT9y3vI.cs |
High entropy of concatenated method names: 'MmffT3XATF', 'bhcfiNdEPA', 'KUlfD2JnYL', 'L52fW5j5EV', 'iwpfGBMyDq', 'FY2fFiV4G7', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, MrT2AfiN81blrM7ofh.cs |
High entropy of concatenated method names: 'Fil68wRVKh', 'uV96PgsEAu', 'wGW67Fa14W', 'iLi6SF1QQU', 'R3D6lF5cYk', 'YyD6wFTLn3', 'r5s6cAOTPE', 'uT26fMxvgs', 'Axv6dcNtid', 'EWW62x0JWN' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, V3prQuAj3Ol4OExEGv.cs |
High entropy of concatenated method names: 'VPKfngqLZD', 'ctvf4lSqmn', 't6Kf6sTWFR', 'eN6frFr9NH', 'DqvfsFFBEL', 'g7Of1PbsFF', 'nL5foJpBCl', 'ArufXnEolv', 'WFnfqPavWT', 'fMJfYK3LF9' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, ywb8dSUlRHcITytTBP.cs |
High entropy of concatenated method names: 'v1Trghfk51', 'zWCrt9RyXT', 'qRn6DM2aH8', 'rF36WuVWFf', 'Yfi6FbSECt', 'j4d6jpQxwE', 'tLn6hNNvuC', 'duX6NaTxcD', 'eLs6kfqbPN', 'wQq6KvsqVR' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, L0scfAZViKfKXE4Hg6.cs |
High entropy of concatenated method names: 'GoUsHUjcLE', 'l4Bs4ciWeA', 'A1lsrYmU5u', 'J6ls12hdkG', 'pH4soEeAmi', 'r6Vryqm8uA', 'MWhrMRmkfC', 'X3UrA9E4wb', 'adyrJkqPpD', 'BJ8rB91Q1I' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, JUWfI2zWuid0Q7O0ZT.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'FvCdVBYBY3', 'MMcdlKhE7Q', 'R7bdwcBg53', 'grDdcV5P3D', 'Iokdfwtdsv', 'vV0ddqQBBj', 'DiNd2bJVBk' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, lw2l7RhtXX8UM9HjGF.cs |
High entropy of concatenated method names: 'qwxOHLyv85', 'xo4On4KijT', 'tGtO4MU2X3', 'UhqO64N7nm', 'e9FOrnTEMX', 'mdbOsDJZkN', 'ie2O1uJP7v', 'RAKOoD8Zdj', 'IiROXmk3Un', 'mu1Oqlj2iW' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, LaiKv15nLAvK9HiqXE.cs |
High entropy of concatenated method names: 'KJodaK2pB4', 'OUgdOLHLjB', 'FcTdQEkgb6', 'GxDdnTyJVg', 'Uhdd4kL5ud', 'sKvdrq8S3n', 'sCpdsG6tT0', 'H82fAm2Mn1', 'OFOfJ69G0i', 'LQvfBe4xgp' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, UhXjfdrLjoQJACNZXp.cs |
High entropy of concatenated method names: 'k8AV7MDF0Z', 'gIOVS8JeGK', 'mYtVT1H95B', 'StuViTsro7', 'grVVW8cgVJ', 'Tt2VFSFurG', 'M7AVhqmqlC', 'oCPVNN60k4', 'QoBVK4Aqu3', 'smoVL7l3c3' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, yfLSmUJL7Z9ql1Bg8U.cs |
High entropy of concatenated method names: 'QTj1n7xIKB', 'npi16AYrGb', 'xAs1sceBq5', 'tUisIqWQAK', 'MgVszLQQd6', 'Q0D15V1Y1m', 'Dkd1a1vQGX', 'owu1mkSP8e', 'o081O2TZHc', 'yrZ1QecFU0' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, U3WXjgkIoYPtq8pCPP.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'uWXmBfuuuN', 'yxUmIZRFLx', 'Ms5mzKCgrU', 'n4BO5S4upY', 'q0oOakFsbK', 'YUMOmyKRPt', 'wonOOOvjan', 'ipKWIs4qRCkvW7cqTIw' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, jCHoQs4nofL44OacKx.cs |
High entropy of concatenated method names: 'D9JZv46aD', 'rvC8A2YCm', 'iPMPwl4E6', 'tC1trdkLt', 'y67SMuhcv', 'MyJbUeo1v', 'WnpxdWkCYxRA8Cqd8F', 'tORjKHPvhoxhZEc91h', 'mref77Ptw', 'vVZ2ymoiE' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, NlMwpiGmyTNGuLogXe.cs |
High entropy of concatenated method names: 'tOacqJh5GA', 'FVacYsgqrj', 'ToString', 'xlQcnZlWp7', 'eMdc4fbHbx', 'a3Zc6JGUdo', 'grYcrMfBZK', 'sOLcsRU0UH', 'o3vc1emvxq', 'v8JcoHUN0F' |
Source: 0.2.rNNA.exe.42b9690.11.raw.unpack, RTRqeKChxrikX2k2eR.cs |
High entropy of concatenated method names: 'GiNVSGKySP8VUaHonO9', 'zN47tQKTVDeCUjajadx', 'eSEsfXAcdM', 'qjLsdhHFta', 'sAJs27ejYo', 'BPuhBiKwWQiXDZXhk26', 'EII46jKvsnjp64ihgik' |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\Desktop\rNNA.exe TID: 4364 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7472 |
Thread sleep time: -7378697629483816s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep count: 32 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -29514790517935264s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7512 |
Thread sleep count: 3385 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99796s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99468s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99357s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99249s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7512 |
Thread sleep count: 6474 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -99031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98921s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98592s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98479s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98130s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -98015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97787s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97671s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97452s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -97000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96671s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96452s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -96014s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95796s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95577s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95468s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -95031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -94921s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -94812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -94703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -94593s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe TID: 7504 |
Thread sleep time: -94484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7484 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -20291418481080494s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -100000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7840 |
Thread sleep count: 1444 > 30 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99890s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7840 |
Thread sleep count: 7222 > 30 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99781s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99671s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99562s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99453s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99343s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99234s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99125s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -99015s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98906s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98796s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98686s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98577s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98467s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98359s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98250s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98140s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -98031s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97921s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97812s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97703s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97593s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97482s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97375s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97265s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97156s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -97046s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96937s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96828s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96718s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96609s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96499s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96390s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96281s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96171s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -96062s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95953s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95842s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95734s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95624s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95515s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -95406s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe TID: 7832 |
Thread sleep time: -922337203685477s >= -30000s |
|
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99796 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99687 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99578 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99468 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99357 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99249 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99140 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 99031 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98921 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98812 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98703 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98592 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98479 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98359 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98250 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98130 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 98015 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97906 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97787 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97671 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97562 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97452 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97343 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97234 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97109 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 97000 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96890 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96781 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96671 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96562 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96452 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96343 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96234 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96125 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 96014 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95906 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95796 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95687 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95577 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95468 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95359 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95250 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95140 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 95031 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 94921 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 94812 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 94703 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 94593 |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Thread delayed: delay time: 94484 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 100000 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99890 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99781 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99671 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99562 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99453 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99343 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99234 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99125 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 99015 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98906 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98796 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98686 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98577 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98467 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98359 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98250 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98140 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 98031 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97921 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97812 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97703 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97593 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97482 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97375 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97265 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97156 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 97046 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96937 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96828 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96718 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96609 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96499 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96390 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96281 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96171 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 96062 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95953 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95842 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95734 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95624 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95515 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 95406 |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Users\user\Desktop\rNNA.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Users\user\Desktop\rNNA.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\rNNA.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Users\user\AppData\Roaming\wZnyuP.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Users\user\AppData\Roaming\wZnyuP.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\wZnyuP.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|