Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E8430 |
0_2_010E8430 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E8811 |
0_2_010E8811 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E7000 |
0_2_010E7000 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E7340 |
0_2_010E7340 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E84D1 |
0_2_010E84D1 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E732E |
0_2_010E732E |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_010E7878 |
0_2_010E7878 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A4758 |
0_2_012A4758 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A7178 |
0_2_012A7178 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A001E |
0_2_012A001E |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A0040 |
0_2_012A0040 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A4749 |
0_2_012A4749 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 0_2_012A0918 |
0_2_012A0918 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014A41F8 |
9_2_014A41F8 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014AA998 |
9_2_014AA998 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014AEB71 |
9_2_014AEB71 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014A4AC8 |
9_2_014A4AC8 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014A3EB0 |
9_2_014A3EB0 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_014AADF0 |
9_2_014AADF0 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D43468 |
9_2_06D43468 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D465C0 |
9_2_06D465C0 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D455A8 |
9_2_06D455A8 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D47D40 |
9_2_06D47D40 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D4B1F8 |
9_2_06D4B1F8 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D47660 |
9_2_06D47660 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D45CAB |
9_2_06D45CAB |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D4E378 |
9_2_06D4E378 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D40040 |
9_2_06D40040 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06E32003 |
9_2_06E32003 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06E32008 |
9_2_06E32008 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Code function: 9_2_06D40006 |
9_2_06D40006 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_01048422 |
10_2_01048422 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_01047000 |
10_2_01047000 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_01047340 |
10_2_01047340 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010484D1 |
10_2_010484D1 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_0104732E |
10_2_0104732E |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_01047878 |
10_2_01047878 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A395A |
10_2_010A395A |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A0030 |
10_2_010A0030 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A0040 |
10_2_010A0040 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A63F0 |
10_2_010A63F0 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A0918 |
10_2_010A0918 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_010A39C5 |
10_2_010A39C5 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A0468 |
10_2_080A0468 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A0780 |
10_2_080A0780 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A70B5 |
10_2_080A70B5 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080AE880 |
10_2_080AE880 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080AECB8 |
10_2_080AECB8 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080AE448 |
10_2_080AE448 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A0458 |
10_2_080A0458 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A0771 |
10_2_080A0771 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A5CF0 |
10_2_080A5CF0 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A5D00 |
10_2_080A5D00 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 10_2_080A16E8 |
10_2_080A16E8 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018D41F8 |
15_2_018D41F8 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018DA998 |
15_2_018DA998 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018D4AC8 |
15_2_018D4AC8 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018DADE2 |
15_2_018DADE2 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018D3EB0 |
15_2_018D3EB0 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_018DEC59 |
15_2_018DEC59 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_06F13460 |
15_2_06F13460 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_06F17658 |
15_2_06F17658 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_06F10040 |
15_2_06F10040 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_06F10006 |
15_2_06F10006 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_07002002 |
15_2_07002002 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_07002008 |
15_2_07002008 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_071C5BD1 |
15_2_071C5BD1 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_071C07F4 |
15_2_071C07F4 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_071CDC38 |
15_2_071CDC38 |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Code function: 15_2_071CDC28 |
15_2_071CDC28 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D98430 |
17_2_00D98430 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D98758 |
17_2_00D98758 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D97000 |
17_2_00D97000 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D97340 |
17_2_00D97340 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D984D1 |
17_2_00D984D1 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D9737A |
17_2_00D9737A |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D9732E |
17_2_00D9732E |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_00D97878 |
17_2_00D97878 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0489395A |
17_2_0489395A |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_04892091 |
17_2_04892091 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_04890007 |
17_2_04890007 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_04890040 |
17_2_04890040 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_048963F0 |
17_2_048963F0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_048939C5 |
17_2_048939C5 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_04890918 |
17_2_04890918 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549E448 |
17_2_0549E448 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05490458 |
17_2_05490458 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05490468 |
17_2_05490468 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549E42E |
17_2_0549E42E |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05490771 |
17_2_05490771 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05490780 |
17_2_05490780 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549ECB8 |
17_2_0549ECB8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549E870 |
17_2_0549E870 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549E880 |
17_2_0549E880 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_0549B7A0 |
17_2_0549B7A0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05495D00 |
17_2_05495D00 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05495CF0 |
17_2_05495CF0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 17_2_05499BB2 |
17_2_05499BB2 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_014641F8 |
22_2_014641F8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_0146EA60 |
22_2_0146EA60 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_01464AC8 |
22_2_01464AC8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_0146ACD0 |
22_2_0146ACD0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_01463EB0 |
22_2_01463EB0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE3468 |
22_2_06AE3468 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE55A8 |
22_2_06AE55A8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE65C0 |
22_2_06AE65C0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE7D40 |
22_2_06AE7D40 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AEB208 |
22_2_06AEB208 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE7660 |
22_2_06AE7660 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE5CC0 |
22_2_06AE5CC0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AEE378 |
22_2_06AEE378 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE0040 |
22_2_06AE0040 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06BD1DC8 |
22_2_06BD1DC8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06BD1DC2 |
22_2_06BD1DC2 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 22_2_06AE0006 |
22_2_06AE0006 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_02ED39D1 |
25_2_02ED39D1 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_02ED6330 |
25_2_02ED6330 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_02ED0040 |
25_2_02ED0040 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_02ED0918 |
25_2_02ED0918 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_03098758 |
25_2_03098758 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_03098422 |
25_2_03098422 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_03097340 |
25_2_03097340 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_03097000 |
25_2_03097000 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_030984D1 |
25_2_030984D1 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_0309732E |
25_2_0309732E |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_0309737A |
25_2_0309737A |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_03097878 |
25_2_03097878 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD0468 |
25_2_08AD0468 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD0780 |
25_2_08AD0780 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD70B5 |
25_2_08AD70B5 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08ADE880 |
25_2_08ADE880 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08ADECB8 |
25_2_08ADECB8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08ADE448 |
25_2_08ADE448 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD0458 |
25_2_08AD0458 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD0771 |
25_2_08AD0771 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD7942 |
25_2_08AD7942 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD7950 |
25_2_08AD7950 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD5CF0 |
25_2_08AD5CF0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD5D00 |
25_2_08AD5D00 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08ADF268 |
25_2_08ADF268 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD16E8 |
25_2_08AD16E8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 25_2_08AD16D9 |
25_2_08AD16D9 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_015EEA51 |
28_2_015EEA51 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_015E4AC8 |
28_2_015E4AC8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_015EACC2 |
28_2_015EACC2 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_015E3EB0 |
28_2_015E3EB0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_015E41F8 |
28_2_015E41F8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA3468 |
28_2_06DA3468 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA65C0 |
28_2_06DA65C0 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA55A8 |
28_2_06DA55A8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA7D40 |
28_2_06DA7D40 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DAB1F8 |
28_2_06DAB1F8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA7660 |
28_2_06DA7660 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA5CAB |
28_2_06DA5CAB |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DAE378 |
28_2_06DAE378 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA0040 |
28_2_06DA0040 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06E91DC8 |
28_2_06E91DC8 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06E91DC3 |
28_2_06E91DC3 |
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Code function: 28_2_06DA0007 |
28_2_06DA0007 |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
|
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rasman.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rtutils.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: mswsock.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: winhttp.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: schannel.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: edputil.dll |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Section loaded: windowscodecs.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: urlmon.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: iertutil.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: srvcli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: netutils.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: propsys.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windowscodecs.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: edputil.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: appresolver.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: slc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sppc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasman.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rtutils.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mswsock.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: winhttp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: schannel.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: edputil.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: urlmon.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: iertutil.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: srvcli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: netutils.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: propsys.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windowscodecs.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: edputil.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: appresolver.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: slc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sppc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasman.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rtutils.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mswsock.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: winhttp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: schannel.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Section loaded: edputil.dll |
|
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, jwvBObYx4KVfbRPv8H.cs |
High entropy of concatenated method names: 'dNitCBtyDX', 'LGxtKyc2Gf', 'DtStBGq7Dl', 'Kdrt0CgSW4', 'RxYtOuOUBA', 'aJNt4TKylH', 'ruLyIUVPrB4ueT7al4', 'TQppsVRICj7DY6vPLK', 'XNjtt2Uy2r', 'eU9tLcgiPM' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, O6JYRBbGpphBJ1wiTr.cs |
High entropy of concatenated method names: 'aUYhEDxDLg', 'jkUhlEPtOR', 'KF3hnKYmbg', 'qlEhuWfPdf', 'gXEhOMMUeu', 'qGeh4gPbUF', 'RAAhsQnnWg', 'BbOhrhdd7v', 'TOJheUFipl', 'd4th5ed66k' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, uqb8829qSQEKSUUyX8.cs |
High entropy of concatenated method names: 'rtWrkCm7DB', 'lP6rQhnIAF', 'LbBrNnnEVw', 'EuYrIBOX1r', 'iRDr7jdZVC', 'mnXrpxDqFf', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, qFYK852BrT3Kkc2vmV.cs |
High entropy of concatenated method names: 'ToString', 'zP04mHM7LT', 'Jtv4QDWxdF', 'yyK4NSxP4u', 'Lde4Ii4Bf0', 'TOr4pGF67I', 'RdY4xyfdl2', 'YiK4TMLoL9', 'Mbu4VmHe83', 'RHX4iL1328' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, jltxWJLFOkrowWdHRa.cs |
High entropy of concatenated method names: 'seFLSBnOpc', 'QE9LZdSWex', 'bJoLvnWHk7', 'A0kLhD1IBT', 'P6PLaQOMmc', 'ENOL1Jh0eU', 'dtGLCl5PkZ', 'tDrLKnIP87', 'cCRLWJLpjg', 'ooxLBaYBH8' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, NrduLADURKlOmqWg36.cs |
High entropy of concatenated method names: 'Dispose', 'dMltdwbRA3', 'SVqgQJoKWO', 'wTuJJWsrbE', 'j8qtMIh6J0', 'lT7tz3Jerk', 'ProcessDialogKey', 'Vn7gwqUXMi', 'jSZgtjOB2E', 'v1iggpDuKl' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, aglaL3SBeIfXbEHPr5.cs |
High entropy of concatenated method names: 'yXyjD4ccT', 'rmIEgF0Lt', 'KvnlWhZ9v', 'MYg9jXo9Q', 'AoduPg6vq', 'aTJA2fql4', 'vfabRaTseTihmVIBbq', 'oqC9ECJ7jnFvOil5Y8', 'EcgowA4VcZUR6YVWVb', 'wJOr9GZBk' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, lsSq27I0hnIdfvPF4e.cs |
High entropy of concatenated method names: 'GS4rZIyRch', 'krfrvMo2Vh', 'zcgrhuAU1d', 'E8gra6OC98', 'MHWr1Nt9K3', 'PFCrCv9ELL', 'TLTrKOkL8C', 'knJrWVXJvv', 'mQfrBBRdId', 'qYRr0dw2Jh' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, a6JHtZGdpnrIbdwyXv.cs |
High entropy of concatenated method names: 'ViFet6IgGt', 'ExfeLAf10o', 'iqIeqd02sw', 'LwXeZDAcij', 'dBuevhFKOK', 'ufuea1s2Yn', 'bI0e1n1dkH', 'pCwrYGqcwX', 'eqTrffr0Jh', 'j6hrdy0lUf' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, IK1XrNJvr7PPm1j0MU.cs |
High entropy of concatenated method names: 'LyUsfGYeW3', 'dXcsMSiTm6', 'Cb7rwVBCEb', 'G0drtoQdIw', 'woPsmJRtcK', 'J2WsXFjci4', 'kCasbnGPaV', 'Pbts7Fux4c', 'eM8scJxOuU', 'lgCsUgB5Gu' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, BdI41qFnRSKwjr8vRsn.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Svq57XkBVw', 'Gf35cnPVvI', 'YUK5UeVrNG', 'CW85o2AK86', 'l2l5GLIyyM', 'tG452jZ1sY', 'vsJ5YkQVty' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, Knh1rZctAHXyTagCjl.cs |
High entropy of concatenated method names: 'pwJCDuvOXY', 'V7VC6ZraL8', 'VQUCj1a4HL', 'XqoCETSHf1', 'TbwCP3iO7c', 'oDTClQYMK3', 'aXoC9ZW6fT', 'UwvCnafP8F', 'UtwCuxdeZb', 'seFCAQpgIv' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, BQ07W6faPBvr0ngALj.cs |
High entropy of concatenated method names: 'GPx1Su0hbi', 'epd1vD3fbv', 'Ii21aL7h0G', 'vb41C8yrg5', 'cSX1KHZ5iX', 'YEaaGuNu4N', 'fkja2cuZKI', 'tVlaYSwTkW', 'i1fafgFgFS', 'ylrad0irmy' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, hbZNRJKn3pZuk9vCcl.cs |
High entropy of concatenated method names: 'x4uv79T57D', 'MmjvcWuxcC', 'O66vU2FRJw', 'RwNvoKedMK', 'N7gvGhACcU', 'P6Mv2oxrXw', 'DnwvYjkEQy', 'YmhvfXTs1J', 'khavdUYoEm', 'wgYvMadjZ6' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, WHHN6qPHh8Gp7ChIm9.cs |
High entropy of concatenated method names: 'PqbCZSZJeO', 'R5YChTqG27', 'Y4EC1H5Xgc', 'gOl1MntkaJ', 'bcS1z063qy', 'yR5CwajvHY', 'x5PCtPNV8N', 'Lb1Cgs6wGv', 'PCFCLGPFeU', 'UUGCqhuF7N' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, M2rrVhU3FjFAhrKFRP.cs |
High entropy of concatenated method names: 'C3lsBYVfUZ', 'z8Vs0eDmTu', 'ToString', 'TlgsZ5c0eg', 'L4fsvXrPp0', 'wtesh7u6Rr', 'lonsak2A59', 'Db5s1fhOLX', 'jsIsCLlpL3', 'RPXsKp3rU2' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, i0WP6bFCToAWJjStbBE.cs |
High entropy of concatenated method names: 'soPeDdAJ4U', 'kBOe6TZYNG', 'vT8ejZRa3Z', 's85eEItWvs', 'Uv0ePtWMGe', 'Hryelhb4BA', 'Gdle9Y7x2A', 'i4nen1cjPy', 'zKTeucFwIc', 'A5veAJxbb3' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, YKiqK78yXUtNKTP13r.cs |
High entropy of concatenated method names: 'lvBO8IFhoK', 'BrUOXeDSph', 'jPxO71OQkR', 'jkfOcHEbeR', 'dZcOQK3dAq', 'tFCONLucdK', 'v5LOIuyiMu', 'cTbOpYu4y7', 'j9qOx53wkT', 'rmaOT9VkhZ' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, acsoXDaJfaCEw9XyjA.cs |
High entropy of concatenated method names: 'dq9aPXxkoT', 'SRoa99nncq', 'qv5hN84FxZ', 'oeUhIBg5eC', 'CwGhpyTf4t', 'EdshxdVGK9', 'W3phTnVqKg', 'a6IhVRkTcY', 'Q2QhiD5Zjt', 'rQgh8ns60g' |
Source: 0.2.BKG#SGN2106728.PDF.exe.88a0000.7.raw.unpack, p02NCl3dFf9aHThU9q.cs |
High entropy of concatenated method names: 'Gbr3nuweOX', 'x2G3u5SUO5', 'cgd3kL46ly', 'lpZ3QJ00X1', 'Sxc3IZ8Vxe', 'gaH3pQi5bG', 'd6N3TSIogC', 'vgC3VyeswW', 'USG38SFwJW', 'pi23mpWesb' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, jwvBObYx4KVfbRPv8H.cs |
High entropy of concatenated method names: 'dNitCBtyDX', 'LGxtKyc2Gf', 'DtStBGq7Dl', 'Kdrt0CgSW4', 'RxYtOuOUBA', 'aJNt4TKylH', 'ruLyIUVPrB4ueT7al4', 'TQppsVRICj7DY6vPLK', 'XNjtt2Uy2r', 'eU9tLcgiPM' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, O6JYRBbGpphBJ1wiTr.cs |
High entropy of concatenated method names: 'aUYhEDxDLg', 'jkUhlEPtOR', 'KF3hnKYmbg', 'qlEhuWfPdf', 'gXEhOMMUeu', 'qGeh4gPbUF', 'RAAhsQnnWg', 'BbOhrhdd7v', 'TOJheUFipl', 'd4th5ed66k' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, uqb8829qSQEKSUUyX8.cs |
High entropy of concatenated method names: 'rtWrkCm7DB', 'lP6rQhnIAF', 'LbBrNnnEVw', 'EuYrIBOX1r', 'iRDr7jdZVC', 'mnXrpxDqFf', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, qFYK852BrT3Kkc2vmV.cs |
High entropy of concatenated method names: 'ToString', 'zP04mHM7LT', 'Jtv4QDWxdF', 'yyK4NSxP4u', 'Lde4Ii4Bf0', 'TOr4pGF67I', 'RdY4xyfdl2', 'YiK4TMLoL9', 'Mbu4VmHe83', 'RHX4iL1328' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, jltxWJLFOkrowWdHRa.cs |
High entropy of concatenated method names: 'seFLSBnOpc', 'QE9LZdSWex', 'bJoLvnWHk7', 'A0kLhD1IBT', 'P6PLaQOMmc', 'ENOL1Jh0eU', 'dtGLCl5PkZ', 'tDrLKnIP87', 'cCRLWJLpjg', 'ooxLBaYBH8' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, NrduLADURKlOmqWg36.cs |
High entropy of concatenated method names: 'Dispose', 'dMltdwbRA3', 'SVqgQJoKWO', 'wTuJJWsrbE', 'j8qtMIh6J0', 'lT7tz3Jerk', 'ProcessDialogKey', 'Vn7gwqUXMi', 'jSZgtjOB2E', 'v1iggpDuKl' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, aglaL3SBeIfXbEHPr5.cs |
High entropy of concatenated method names: 'yXyjD4ccT', 'rmIEgF0Lt', 'KvnlWhZ9v', 'MYg9jXo9Q', 'AoduPg6vq', 'aTJA2fql4', 'vfabRaTseTihmVIBbq', 'oqC9ECJ7jnFvOil5Y8', 'EcgowA4VcZUR6YVWVb', 'wJOr9GZBk' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, lsSq27I0hnIdfvPF4e.cs |
High entropy of concatenated method names: 'GS4rZIyRch', 'krfrvMo2Vh', 'zcgrhuAU1d', 'E8gra6OC98', 'MHWr1Nt9K3', 'PFCrCv9ELL', 'TLTrKOkL8C', 'knJrWVXJvv', 'mQfrBBRdId', 'qYRr0dw2Jh' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, a6JHtZGdpnrIbdwyXv.cs |
High entropy of concatenated method names: 'ViFet6IgGt', 'ExfeLAf10o', 'iqIeqd02sw', 'LwXeZDAcij', 'dBuevhFKOK', 'ufuea1s2Yn', 'bI0e1n1dkH', 'pCwrYGqcwX', 'eqTrffr0Jh', 'j6hrdy0lUf' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, IK1XrNJvr7PPm1j0MU.cs |
High entropy of concatenated method names: 'LyUsfGYeW3', 'dXcsMSiTm6', 'Cb7rwVBCEb', 'G0drtoQdIw', 'woPsmJRtcK', 'J2WsXFjci4', 'kCasbnGPaV', 'Pbts7Fux4c', 'eM8scJxOuU', 'lgCsUgB5Gu' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, BdI41qFnRSKwjr8vRsn.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Svq57XkBVw', 'Gf35cnPVvI', 'YUK5UeVrNG', 'CW85o2AK86', 'l2l5GLIyyM', 'tG452jZ1sY', 'vsJ5YkQVty' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, Knh1rZctAHXyTagCjl.cs |
High entropy of concatenated method names: 'pwJCDuvOXY', 'V7VC6ZraL8', 'VQUCj1a4HL', 'XqoCETSHf1', 'TbwCP3iO7c', 'oDTClQYMK3', 'aXoC9ZW6fT', 'UwvCnafP8F', 'UtwCuxdeZb', 'seFCAQpgIv' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, BQ07W6faPBvr0ngALj.cs |
High entropy of concatenated method names: 'GPx1Su0hbi', 'epd1vD3fbv', 'Ii21aL7h0G', 'vb41C8yrg5', 'cSX1KHZ5iX', 'YEaaGuNu4N', 'fkja2cuZKI', 'tVlaYSwTkW', 'i1fafgFgFS', 'ylrad0irmy' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, hbZNRJKn3pZuk9vCcl.cs |
High entropy of concatenated method names: 'x4uv79T57D', 'MmjvcWuxcC', 'O66vU2FRJw', 'RwNvoKedMK', 'N7gvGhACcU', 'P6Mv2oxrXw', 'DnwvYjkEQy', 'YmhvfXTs1J', 'khavdUYoEm', 'wgYvMadjZ6' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, WHHN6qPHh8Gp7ChIm9.cs |
High entropy of concatenated method names: 'PqbCZSZJeO', 'R5YChTqG27', 'Y4EC1H5Xgc', 'gOl1MntkaJ', 'bcS1z063qy', 'yR5CwajvHY', 'x5PCtPNV8N', 'Lb1Cgs6wGv', 'PCFCLGPFeU', 'UUGCqhuF7N' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, M2rrVhU3FjFAhrKFRP.cs |
High entropy of concatenated method names: 'C3lsBYVfUZ', 'z8Vs0eDmTu', 'ToString', 'TlgsZ5c0eg', 'L4fsvXrPp0', 'wtesh7u6Rr', 'lonsak2A59', 'Db5s1fhOLX', 'jsIsCLlpL3', 'RPXsKp3rU2' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, i0WP6bFCToAWJjStbBE.cs |
High entropy of concatenated method names: 'soPeDdAJ4U', 'kBOe6TZYNG', 'vT8ejZRa3Z', 's85eEItWvs', 'Uv0ePtWMGe', 'Hryelhb4BA', 'Gdle9Y7x2A', 'i4nen1cjPy', 'zKTeucFwIc', 'A5veAJxbb3' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, YKiqK78yXUtNKTP13r.cs |
High entropy of concatenated method names: 'lvBO8IFhoK', 'BrUOXeDSph', 'jPxO71OQkR', 'jkfOcHEbeR', 'dZcOQK3dAq', 'tFCONLucdK', 'v5LOIuyiMu', 'cTbOpYu4y7', 'j9qOx53wkT', 'rmaOT9VkhZ' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, acsoXDaJfaCEw9XyjA.cs |
High entropy of concatenated method names: 'dq9aPXxkoT', 'SRoa99nncq', 'qv5hN84FxZ', 'oeUhIBg5eC', 'CwGhpyTf4t', 'EdshxdVGK9', 'W3phTnVqKg', 'a6IhVRkTcY', 'Q2QhiD5Zjt', 'rQgh8ns60g' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4a26560.3.raw.unpack, p02NCl3dFf9aHThU9q.cs |
High entropy of concatenated method names: 'Gbr3nuweOX', 'x2G3u5SUO5', 'cgd3kL46ly', 'lpZ3QJ00X1', 'Sxc3IZ8Vxe', 'gaH3pQi5bG', 'd6N3TSIogC', 'vgC3VyeswW', 'USG38SFwJW', 'pi23mpWesb' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, jwvBObYx4KVfbRPv8H.cs |
High entropy of concatenated method names: 'dNitCBtyDX', 'LGxtKyc2Gf', 'DtStBGq7Dl', 'Kdrt0CgSW4', 'RxYtOuOUBA', 'aJNt4TKylH', 'ruLyIUVPrB4ueT7al4', 'TQppsVRICj7DY6vPLK', 'XNjtt2Uy2r', 'eU9tLcgiPM' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, O6JYRBbGpphBJ1wiTr.cs |
High entropy of concatenated method names: 'aUYhEDxDLg', 'jkUhlEPtOR', 'KF3hnKYmbg', 'qlEhuWfPdf', 'gXEhOMMUeu', 'qGeh4gPbUF', 'RAAhsQnnWg', 'BbOhrhdd7v', 'TOJheUFipl', 'd4th5ed66k' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, uqb8829qSQEKSUUyX8.cs |
High entropy of concatenated method names: 'rtWrkCm7DB', 'lP6rQhnIAF', 'LbBrNnnEVw', 'EuYrIBOX1r', 'iRDr7jdZVC', 'mnXrpxDqFf', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, qFYK852BrT3Kkc2vmV.cs |
High entropy of concatenated method names: 'ToString', 'zP04mHM7LT', 'Jtv4QDWxdF', 'yyK4NSxP4u', 'Lde4Ii4Bf0', 'TOr4pGF67I', 'RdY4xyfdl2', 'YiK4TMLoL9', 'Mbu4VmHe83', 'RHX4iL1328' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, jltxWJLFOkrowWdHRa.cs |
High entropy of concatenated method names: 'seFLSBnOpc', 'QE9LZdSWex', 'bJoLvnWHk7', 'A0kLhD1IBT', 'P6PLaQOMmc', 'ENOL1Jh0eU', 'dtGLCl5PkZ', 'tDrLKnIP87', 'cCRLWJLpjg', 'ooxLBaYBH8' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, NrduLADURKlOmqWg36.cs |
High entropy of concatenated method names: 'Dispose', 'dMltdwbRA3', 'SVqgQJoKWO', 'wTuJJWsrbE', 'j8qtMIh6J0', 'lT7tz3Jerk', 'ProcessDialogKey', 'Vn7gwqUXMi', 'jSZgtjOB2E', 'v1iggpDuKl' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, aglaL3SBeIfXbEHPr5.cs |
High entropy of concatenated method names: 'yXyjD4ccT', 'rmIEgF0Lt', 'KvnlWhZ9v', 'MYg9jXo9Q', 'AoduPg6vq', 'aTJA2fql4', 'vfabRaTseTihmVIBbq', 'oqC9ECJ7jnFvOil5Y8', 'EcgowA4VcZUR6YVWVb', 'wJOr9GZBk' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, lsSq27I0hnIdfvPF4e.cs |
High entropy of concatenated method names: 'GS4rZIyRch', 'krfrvMo2Vh', 'zcgrhuAU1d', 'E8gra6OC98', 'MHWr1Nt9K3', 'PFCrCv9ELL', 'TLTrKOkL8C', 'knJrWVXJvv', 'mQfrBBRdId', 'qYRr0dw2Jh' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, a6JHtZGdpnrIbdwyXv.cs |
High entropy of concatenated method names: 'ViFet6IgGt', 'ExfeLAf10o', 'iqIeqd02sw', 'LwXeZDAcij', 'dBuevhFKOK', 'ufuea1s2Yn', 'bI0e1n1dkH', 'pCwrYGqcwX', 'eqTrffr0Jh', 'j6hrdy0lUf' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, IK1XrNJvr7PPm1j0MU.cs |
High entropy of concatenated method names: 'LyUsfGYeW3', 'dXcsMSiTm6', 'Cb7rwVBCEb', 'G0drtoQdIw', 'woPsmJRtcK', 'J2WsXFjci4', 'kCasbnGPaV', 'Pbts7Fux4c', 'eM8scJxOuU', 'lgCsUgB5Gu' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, BdI41qFnRSKwjr8vRsn.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Svq57XkBVw', 'Gf35cnPVvI', 'YUK5UeVrNG', 'CW85o2AK86', 'l2l5GLIyyM', 'tG452jZ1sY', 'vsJ5YkQVty' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, Knh1rZctAHXyTagCjl.cs |
High entropy of concatenated method names: 'pwJCDuvOXY', 'V7VC6ZraL8', 'VQUCj1a4HL', 'XqoCETSHf1', 'TbwCP3iO7c', 'oDTClQYMK3', 'aXoC9ZW6fT', 'UwvCnafP8F', 'UtwCuxdeZb', 'seFCAQpgIv' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, BQ07W6faPBvr0ngALj.cs |
High entropy of concatenated method names: 'GPx1Su0hbi', 'epd1vD3fbv', 'Ii21aL7h0G', 'vb41C8yrg5', 'cSX1KHZ5iX', 'YEaaGuNu4N', 'fkja2cuZKI', 'tVlaYSwTkW', 'i1fafgFgFS', 'ylrad0irmy' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, hbZNRJKn3pZuk9vCcl.cs |
High entropy of concatenated method names: 'x4uv79T57D', 'MmjvcWuxcC', 'O66vU2FRJw', 'RwNvoKedMK', 'N7gvGhACcU', 'P6Mv2oxrXw', 'DnwvYjkEQy', 'YmhvfXTs1J', 'khavdUYoEm', 'wgYvMadjZ6' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, WHHN6qPHh8Gp7ChIm9.cs |
High entropy of concatenated method names: 'PqbCZSZJeO', 'R5YChTqG27', 'Y4EC1H5Xgc', 'gOl1MntkaJ', 'bcS1z063qy', 'yR5CwajvHY', 'x5PCtPNV8N', 'Lb1Cgs6wGv', 'PCFCLGPFeU', 'UUGCqhuF7N' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, M2rrVhU3FjFAhrKFRP.cs |
High entropy of concatenated method names: 'C3lsBYVfUZ', 'z8Vs0eDmTu', 'ToString', 'TlgsZ5c0eg', 'L4fsvXrPp0', 'wtesh7u6Rr', 'lonsak2A59', 'Db5s1fhOLX', 'jsIsCLlpL3', 'RPXsKp3rU2' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, i0WP6bFCToAWJjStbBE.cs |
High entropy of concatenated method names: 'soPeDdAJ4U', 'kBOe6TZYNG', 'vT8ejZRa3Z', 's85eEItWvs', 'Uv0ePtWMGe', 'Hryelhb4BA', 'Gdle9Y7x2A', 'i4nen1cjPy', 'zKTeucFwIc', 'A5veAJxbb3' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, YKiqK78yXUtNKTP13r.cs |
High entropy of concatenated method names: 'lvBO8IFhoK', 'BrUOXeDSph', 'jPxO71OQkR', 'jkfOcHEbeR', 'dZcOQK3dAq', 'tFCONLucdK', 'v5LOIuyiMu', 'cTbOpYu4y7', 'j9qOx53wkT', 'rmaOT9VkhZ' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, acsoXDaJfaCEw9XyjA.cs |
High entropy of concatenated method names: 'dq9aPXxkoT', 'SRoa99nncq', 'qv5hN84FxZ', 'oeUhIBg5eC', 'CwGhpyTf4t', 'EdshxdVGK9', 'W3phTnVqKg', 'a6IhVRkTcY', 'Q2QhiD5Zjt', 'rQgh8ns60g' |
Source: 0.2.BKG#SGN2106728.PDF.exe.4980340.2.raw.unpack, p02NCl3dFf9aHThU9q.cs |
High entropy of concatenated method names: 'Gbr3nuweOX', 'x2G3u5SUO5', 'cgd3kL46ly', 'lpZ3QJ00X1', 'Sxc3IZ8Vxe', 'gaH3pQi5bG', 'd6N3TSIogC', 'vgC3VyeswW', 'USG38SFwJW', 'pi23mpWesb' |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1200000 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199875 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199766 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199656 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199547 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199437 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199328 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199219 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199109 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199000 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1200000 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199871 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199765 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199656 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199546 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199437 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199328 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199218 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199109 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198999 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198890 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198781 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198572 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198406 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198281 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198165 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197926 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197807 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197687 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197578 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197468 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197359 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197249 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199936 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199828 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199719 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199589 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199484 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199375 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199240 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199938 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199825 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199719 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199594 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196360 |
|
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 6804 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6504 |
Thread sleep count: 7408 > 30 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7200 |
Thread sleep time: -3689348814741908s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7048 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7240 |
Thread sleep time: -4611686018427385s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5660 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -32281802128991695s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99873s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99764s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99646s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -99078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -98078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -97091s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96655s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -96109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -95995s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -95875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -95762s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -95656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1200000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe TID: 7376 |
Thread sleep time: -1199000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7300 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -35971150943733603s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -100000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99875s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99765s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99656s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99546s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99437s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99328s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99218s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99109s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -99000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98890s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98781s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98672s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98562s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98453s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98343s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98225s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98109s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -98000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97881s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97750s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97610s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97487s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97359s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -97035s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -96906s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -96654s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1200000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199871s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199765s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199656s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199546s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199437s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199328s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199218s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1199109s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198999s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198890s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198781s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198572s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198406s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198281s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1198165s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197926s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197807s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197687s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197578s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197468s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197359s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe TID: 7632 |
Thread sleep time: -1197249s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 7812 |
Thread sleep time: -922337203685477s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep count: 39 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -35971150943733603s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -100000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99843s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8160 |
Thread sleep count: 3754 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99734s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8160 |
Thread sleep count: 6097 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99625s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99515s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99406s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99291s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99187s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -99078s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98968s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98859s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98750s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98640s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98531s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98422s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98312s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98203s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -98093s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97984s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97875s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97765s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97656s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97547s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97437s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97328s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97218s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97109s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -97000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96890s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96781s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96672s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96561s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96442s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -96281s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199936s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199828s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199719s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199589s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199484s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199375s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199240s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1199110s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198985s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198860s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198735s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198610s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198485s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198360s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198235s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 8156 |
Thread sleep time: -1198110s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 7032 |
Thread sleep time: -922337203685477s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep count: 36 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -33204139332677172s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -100000s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 1068 |
Thread sleep count: 4139 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99875s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 1068 |
Thread sleep count: 5660 > 30 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99766s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99656s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99547s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99424s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99297s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99187s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -99050s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98891s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98759s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98625s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98345s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98219s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -98103s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -97741s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -97637s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -96986s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -96840s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -96728s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -96411s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -96030s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -95922s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -95813s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199938s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199825s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199719s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199594s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199485s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199360s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199235s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1199110s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198985s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198860s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198735s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198610s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198485s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198360s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198235s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1198110s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197985s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197860s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197735s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197610s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197485s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197360s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197235s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1197110s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196985s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196860s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196735s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196610s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196485s >= -30000s |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe TID: 4996 |
Thread sleep time: -1196360s >= -30000s |
|
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99873 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99764 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99646 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99515 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99406 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99297 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99187 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 99078 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98968 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98859 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98750 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98625 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98515 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98406 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98297 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98187 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 98078 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97968 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97859 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97750 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97640 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97531 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97421 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97312 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97203 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 97091 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96984 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96875 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96765 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96655 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96547 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96437 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96328 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96218 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 96109 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 95995 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 95875 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 95762 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 95656 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1200000 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199875 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199766 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199656 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199547 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199437 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199328 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199219 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199109 |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Thread delayed: delay time: 1199000 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 100000 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99875 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99765 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99656 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99546 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99437 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99328 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99218 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99109 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 99000 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98890 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98781 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98672 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98562 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98453 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98343 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98225 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98109 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 98000 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97881 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97750 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97610 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97487 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97359 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 97035 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 96906 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 96654 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1200000 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199871 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199765 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199656 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199546 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199437 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199328 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199218 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1199109 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198999 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198890 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198781 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198572 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198406 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198281 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1198165 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197926 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197807 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197687 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197578 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197468 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197359 |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Thread delayed: delay time: 1197249 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 100000 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99843 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99734 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99625 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99515 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99406 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99291 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99187 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99078 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98968 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98859 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98750 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98640 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98531 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98422 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98312 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98203 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98093 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97984 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97875 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97765 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97656 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97547 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97437 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97328 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97218 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97109 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97000 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96890 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96781 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96672 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96561 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96442 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96281 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199936 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199828 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199719 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199589 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199484 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199375 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199240 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 922337203685477 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 100000 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99875 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99766 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99656 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99547 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99424 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99297 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99187 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 99050 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98891 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98759 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98625 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98345 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98219 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 98103 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97741 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 97637 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96986 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96840 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96728 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96411 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 96030 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 95922 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 95813 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199938 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199825 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199719 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199594 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1199110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1198110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197360 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197235 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1197110 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196985 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196860 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196735 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196610 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196485 |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Thread delayed: delay time: 1196360 |
|
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\BKG#SGN2106728.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\eDnxmGWzJ.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
|
Source: C:\Users\user\AppData\Roaming\BjTxJte\BjTxJte.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
|