Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.81.130.139 |
Source: powershell.exe, 00000002.00000002.2076162638.000000000319D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: powershell.exe, 00000002.00000002.2088828355.0000000007902000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microsoft/ |
Source: Zoom.exe, 00000000.00000002.4517013238.000000000140C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: Zoom.exe, 00000000.00000002.4517013238.00000000013D1000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.0.dr | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: powershell.exe, 00000002.00000002.2087313785.000000000608B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.2077345397.0000000005176000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2088828355.0000000007902000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2077345397.0000000005021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000002.00000002.2077345397.0000000005176000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2088828355.0000000007902000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.2077345397.0000000005021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore6lBjq |
Source: powershell.exe, 00000002.00000002.2087313785.000000000608B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.2087313785.000000000608B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.2087313785.000000000608B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/WebDriver.dll |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/chromedriver.exe |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/msedgedriver.exe |
Source: powershell.exe, 00000002.00000002.2077345397.0000000005176000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2088828355.0000000007902000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.2087313785.000000000608B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: Zoom.exe, 00000000.00000002.4519895828.000000000331C000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000000.00000002.4519895828.0000000003133000.00000004.00000800.00020000.00000000.sdmp, Zoom.exe, 00000004.00000002.2363736434.0000000002D31000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/2152978/23354rCannot |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_015B40C2 | 0_2_015B40C2 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_015B4258 | 0_2_015B4258 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_015B14D0 | 0_2_015B14D0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_015B14E0 | 0_2_015B14E0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF1600 | 0_2_06DF1600 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF6369 | 0_2_06DF6369 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF40E0 | 0_2_06DF40E0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF0D30 | 0_2_06DF0D30 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF09E8 | 0_2_06DF09E8 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF3695 | 0_2_06DF3695 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF642D | 0_2_06DF642D |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF6372 | 0_2_06DF6372 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF40D0 | 0_2_06DF40D0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF4038 | 0_2_06DF4038 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF5E3A | 0_2_06DF5E3A |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF5E31 | 0_2_06DF5E31 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_06DF5F18 | 0_2_06DF5F18 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07690D75 | 0_2_07690D75 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_076921A0 | 0_2_076921A0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07691F01 | 0_2_07691F01 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07691F10 | 0_2_07691F10 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_076BEA50 | 0_2_076BEA50 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_076B3960 | 0_2_076B3960 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_076BC7E0 | 0_2_076BC7E0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_076C8C20 | 0_2_076C8C20 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07704EC0 | 0_2_07704EC0 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07700D7F | 0_2_07700D7F |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_0770E17C | 0_2_0770E17C |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_07700DE6 | 0_2_07700DE6 |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_0770535B | 0_2_0770535B |
Source: C:\Users\user\Desktop\Zoom.exe | Code function: 0_2_0853EEA8 | 0_2_0853EEA8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 2_2_04D813A5 | 2_2_04D813A5 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 2_2_04D88B00 | 2_2_04D88B00 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_011514D0 | 4_2_011514D0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_011514E0 | 4_2_011514E0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B1E | 4_2_01151B1E |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B07 | 4_2_01151B07 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B33 | 4_2_01151B33 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B4A | 4_2_01151B4A |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B7A | 4_2_01151B7A |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B62 | 4_2_01151B62 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151B92 | 4_2_01151B92 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01153BEF | 4_2_01153BEF |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151AA8 | 4_2_01151AA8 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151AA8 | 4_2_01151AA8 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01151AF2 | 4_2_01151AF2 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01153CA2 | 4_2_01153CA2 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_01152F25 | 4_2_01152F25 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B5150 | 4_2_052B5150 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B4DF0 | 4_2_052B4DF0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B5142 | 4_2_052B5142 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B4DE0 | 4_2_052B4DE0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B9AF8 | 4_2_052B9AF8 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_052B9AF3 | 4_2_052B9AF3 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_0530E160 | 4_2_0530E160 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_05306828 | 4_2_05306828 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_05300280 | 4_2_05300280 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_0530076D | 4_2_0530076D |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_05302128 | 4_2_05302128 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_05309958 | 4_2_05309958 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_053048E0 | 4_2_053048E0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 4_2_0530F330 | 4_2_0530F330 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_01311758 | 6_2_01311758 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_013141D1 | 6_2_013141D1 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_01314258 | 6_2_01314258 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_013114E0 | 6_2_013114E0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_013114D0 | 6_2_013114D0 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_01311758 | 6_2_01311758 |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Code function: 6_2_01313DCB | 6_2_01313DCB |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: cryptnet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 320 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31359464925306218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -35000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -34796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -34375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -34231s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -34123s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -34012s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33733s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33624s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33515s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33406s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33296s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33187s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -33077s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32421s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32311s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -32082s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31757s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31528s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31421s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -31093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe TID: 6624 | Thread sleep time: -30109s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5000 | Thread sleep count: 5954 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5248 | Thread sleep count: 259 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4852 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6004 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe TID: 2704 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe TID: 1120 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 35000 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 34796 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 34375 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 34231 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 34123 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 34012 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33859 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33733 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33624 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33515 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33406 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33296 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33187 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 33077 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32968 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32859 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32750 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32640 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32531 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32421 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32311 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32203 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 32082 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31757 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31640 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31528 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31421 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31312 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31203 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 31093 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30984 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30874 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30765 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30656 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30546 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30437 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30328 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30218 | Jump to behavior |
Source: C:\Users\user\Desktop\Zoom.exe | Thread delayed: delay time: 30109 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Zoom.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |