Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.00000000031EC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://45.137.22.250:5 |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EF5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://45.137.22.250:55615 |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://45.137.22.250:55615/ |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EF5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EDC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EF5000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EDC000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002FF7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/ |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/0 |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/CheckConnect |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/CheckConnectResponse |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettings |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettingsResponse |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EF5000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EDC000.00000004.00000800.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002FF7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/GetUpdates |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/GetUpdatesResponse |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.00000000031EC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/SetEnviron |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EF5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/SetEnvironment |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/SetEnvironmentResponse |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdate |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002E61000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdateResponse |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fonts.com |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743045301.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.tiro.com |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.typography.netD |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: ljMiHZ8MwZ.exe, 00000000.00000002.1743316362.0000000007322000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb |
Source: ljMiHZ8MwZ.exe, 00000002.00000002.1876392407.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/geoip |
Source: ljMiHZ8MwZ.exe, ljMiHZ8MwZ.exe, 00000002.00000002.1874957650.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/geoip%USERPEnvironmentROFILE% |
Source: ljMiHZ8MwZ.exe, ljMiHZ8MwZ.exe, 00000002.00000002.1874957650.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.orgcookies//settinString.Removeg |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: ljMiHZ8MwZ.exe, ljMiHZ8MwZ.exe, 00000002.00000002.1874957650.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/ip%appdata% |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: tmp96FD.tmp.2.dr, tmpD0D4.tmp.2.dr, tmpD0B3.tmp.2.dr, tmp971F.tmp.2.dr, tmp9762.tmp.2.dr, tmp9741.tmp.2.dr, tmp9752.tmp.2.dr, tmp9731.tmp.2.dr, tmp96FE.tmp.2.dr, tmpD103.tmp.2.dr, tmp970E.tmp.2.dr, tmp9720.tmp.2.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 2.2.ljMiHZ8MwZ.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 2.2.ljMiHZ8MwZ.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e |
Source: 2.2.ljMiHZ8MwZ.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.raw.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e |
Source: 0.2.ljMiHZ8MwZ.exe.4210910.2.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.raw.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e |
Source: 0.2.ljMiHZ8MwZ.exe.41f8af0.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 00000002.00000002.1874957650.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 00000000.00000002.1741731894.00000000041F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: Process Memory Space: ljMiHZ8MwZ.exe PID: 7348, type: MEMORYSTR | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: Process Memory Space: ljMiHZ8MwZ.exe PID: 7532, type: MEMORYSTR | Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, fveyHcscgRsunRk5tw.cs | High entropy of concatenated method names: 'OdIHVklGB7', 'A0hHUGFMQ8', 'di7HHgDVU3', 'WPhHuZdIF0', 'jecHQtuy81', 'S8EHnCMkGg', 'Dispose', 'LaqemtE7ag', 'lEmeWMFu5u', 'wvpeg8N1fq' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, h3TbBgPKWJM3k3GmXI.cs | High entropy of concatenated method names: 'Bv0Hj9P4vN', 'PoCHI7bXh9', 'tP0HorBdxk', 'IZFHkKqDSB', 'UFwH4dBZ5o', 'ogmHfMfU7I', 'tblHCCM6eU', 'nwbHBP7FxE', 'SsyHNnx5Wn', 'DvtHYPC36J' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, oxFBU42wJTr2UTVcBS.cs | High entropy of concatenated method names: 'gdZWZTamEN', 'cYxWGfDJ6P', 'rqsWvqG85K', 'Q24WMioCkT', 'rNOW5G1gr6', 'jSLWrW6foE', 'SR2WsFrbym', 'hWXW8tYt4w', 'JI0WPWFWqv', 'lU8Wh0W6ir' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, qGWQwo3dZPjlkLfaXEb.cs | High entropy of concatenated method names: 'YktuhfmIYi', 'LD9uzApOq9', 'e62bXRuxUF', 'wm5bICyysQdvmS0Q4XK', 'z8lOOUyLLHyT7DMV13X', 'bHiac7yXndI6kdjUemP', 'hl7PP7yYada2wJVpExC' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, UFuoQeCdlpIA3uNJJl.cs | High entropy of concatenated method names: 'vDVamV7Xnr', 'vJOag5ovPb', 'JaoapdFwQR', 'D7QphduMc9', 'I2ipzGUjRU', 'gt4aXushGK', 'gITa3pQxCc', 'UwGaKQRs84', 'acQadBXrkB', 'SoUaRkv0wZ' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, fRMpebh3HnJSGfKfL5.cs | High entropy of concatenated method names: 'ALF7gxHoIM', 'aPJ7DUGyTh', 'zHi7pDRhFN', 'KDK7aqetw2', 'dLQ7Hk0QyX', 'Sg079EB4Xj', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, qBd4H5tgmR5ZnW4Vei.cs | High entropy of concatenated method names: 'SutDAJlYvu', 'ROiDTD7a6p', 'mTmgouYxdA', 'L8LgkWOIJ0', 'W3Ag4urpy0', 'DrNgfaG3pJ', 'YTHgCpg8YQ', 'DeXgBstkRy', 'pSJgNqq9kK', 'CsugYjNTct' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, EuOpUCriLBxCLqaAMU.cs | High entropy of concatenated method names: 'vOfU8JiVtS', 'kejUh5P7hq', 'SsmeXP6x2t', 'QJie3NWrSU', 'GF1USGkmOm', 'WiyUJ3iYo2', 'WsjULLBDQN', 'kxpUZuaE8e', 'h6cUGQhmVq', 'hBvUvt1s7r' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, CmxdKqWHRvJdY9P2C6.cs | High entropy of concatenated method names: 'Dispose', 'dsu3PnRk5t', 'rm3KI9Ogld', 'Qc9iynxKxx', 'xPb3h5Y0G1', 'lEh3zmDCB4', 'ProcessDialogKey', 'BLgKX3TbBg', 'bWJK3M3k3G', 'fXIKKmRMpe' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, KxSlmh3RWIExw3kFaGD.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z08bHsNTZt', 'ecEb7Gibds', 'qkVbu8Vsq1', 'yOpbbc5rbG', 'kJ0bQvpgRT', 'eCebiuG1RS', 'ywtbnw3DD6' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, xGWxxQzs6QMPuKRFe2.cs | High entropy of concatenated method names: 'Aa47OyMdV0', 'LFy72Jn1d0', 'K3o7xmxHL9', 'n0x7jyVL10', 'TvY7ICrcs6', 'TgC7kWqNRO', 'DvN74adREW', 'pbF7nn2tWa', 'QTQ7wEuCWn', 'VlA7FUj0xI' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, biOSFH33IeY62QRJA5u.cs | High entropy of concatenated method names: 'QlJ7hp51tX', 'MG57zf7uE8', 'JcnuXUOOQD', 'fA8u3qOCi4', 'FSLuKS6IhR', 'rOoudh4wZt', 'ITfuRayqui', 'inZulFFGL1', 'jZNumyFrVi', 'b7UuWxWnYF' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, G5HkYS3K1F7W131Parx.cs | High entropy of concatenated method names: 'ToString', 'VWUu29M9nH', 'MVbuxhGMUF', 'iJ8utawXTD', 'JRLujRBLdW', 'qDkuIy5ybl', 'jxiuo8mK8k', 'wY9ukYXNFp', 'P7KdVQyQjg5MX7td4nQ', 'tHGhUAyF7lc1PN7P3jK' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, qYwR0TMDtDIN8pqpVU.cs | High entropy of concatenated method names: 'BD7U66QRgG', 'nAxUqfollF', 'ToString', 'wlwUm64e64', 'mhHUWUVW0m', 'zHcUgC0Lhx', 'rNTUDVxSBj', 'FU6UpWpA6U', 'FBeUas9IZb', 'a0oU99NcCK' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, LXtXutRj3L0weLOGZY.cs | High entropy of concatenated method names: 'F8c3axFBU4', 'xJT39r2UTV', 'eGN364ahiv', 'us03qOUBd4', 'g4V3VeivHo', 'mSo31uYakG', 'yxG1MyehurFOIaCjcr', 'QK6o1mHaIraxp3BFvG', 'Fv933fjTu5', 'jX53dwsoay' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, UeK7EHGFSG5neVbdSw.cs | High entropy of concatenated method names: 'nbNVs063IM', 'XPBV8TMQUC', 'dUEVPT2A0j', 'ht3VhZ13r1', 'p525tGkInunKOMT2f6S', 'QHQbV4kYEaXYvcxiYYR', 'bClmjgknsESuy7o594T' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, mKU4ufKcuQsUByve7r.cs | High entropy of concatenated method names: 'VItECekKP', 'IqC0W8elS', 'UpHOa6EJf', 'P4NTtkGB1', 'IY6xDZZ3I', 'fIKtwLipq', 'w5Etjeu7NULWdSieki', 'RvXf0NPgYG12aGGDNY', 'f4ae92gPt', 'JYY7gfda3' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, HdUXMlxGN4ahivbs0O.cs | High entropy of concatenated method names: 'uhSg0nX4tU', 'uhdgOdZPyk', 'xR2g2QEytr', 'YUtgxoWcVD', 'L7PgVvKeVs', 'XN5g1erWgM', 'CFpgUHOUVG', 'y7yge176mP', 'DaMgHipFIa', 'XNXg73fxNs' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, YBBGBdLdRgRLbm4owH.cs | High entropy of concatenated method names: 'xJnc2OJVPr', 'HGMcxjHCrF', 'FKEcjp1Lfs', 'bDucIDDW7G', 'lDxckPRHCp', 'Kfvc47gPNf', 'GwDcC0Wj3c', 'bekcBNIuZy', 'a3ocYmRbPR', 'tpEcSZ6mhr' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, SHo6SojuYakG6IgwZL.cs | High entropy of concatenated method names: 'KXOpl6bCye', 'd9ypW5gmQX', 'gyWpDflitr', 'qZLpap8reC', 'Xxcp9K9coy', 'kBwD5BnHfP', 'rftDrFd5BB', 'hhTDsv73gI', 'sEtD8aUT80', 'NJ7DPla2TT' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, qyyPq296Qkh0EGin1j.cs | High entropy of concatenated method names: 'euPdl7mcaD', 'GFpdm8cMPX', 'ARXdWkGCMc', 'J1xdglQem5', 'o1rdDC7DXT', 'GfCdpo0y6C', 'TqadaJe7Qc', 'C0ad9cnMHI', 'aXfdy2Hn7t', 'AVvd6CwsdW' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, whT9VAvWrWdOTj3EWO.cs | High entropy of concatenated method names: 'ToString', 'HV41S9wE0x', 'zBN1IqjnDN', 'aBO1otoC4M', 'Plr1ko0y1i', 'IZB14hmjai', 'j2w1fjqtJA', 'M9a1CtUvUE', 'BbA1BLpqst', 'ogf1Nkre7A' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, Ko28UW3XlevF8QFhQ37.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'D8F7SHgxen', 'lke7Jp3es7', 'U1G7LW9wfa', 'JxR7Z5LvDG', 'Eqe7G2j9V1', 'wMK7vU1pZh', 'Mlo7MJmBYk' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, c0npjGZVC8QoekSSiE.cs | High entropy of concatenated method names: 'oZ7VYCnT0c', 'JNAVJ2y6N2', 'BTqVZ9vKHe', 'rroVGn95O6', 'DtiVIgGoL5', 'l39VoG98lM', 'fLoVkVeIkQ', 'WcPV4I0S9L', 'mTyVffQVVl', 'muOVCunoqX' |
Source: 0.2.ljMiHZ8MwZ.exe.7910000.4.raw.unpack, bD37EoNqtrph9p0XKi.cs | High entropy of concatenated method names: 'ELqaw0Q2pj', 'sKiaFEIPPu', 'ahvaEBSRyN', 'YSVa0Z019T', 'CtZaAwGRaF', 'hXiaOM8Ifk', 'cQaaTGXP8U', 'z1Ha2oD9Jw', 'BdPax0uMoO', 'yk7at26fk1' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, fveyHcscgRsunRk5tw.cs | High entropy of concatenated method names: 'OdIHVklGB7', 'A0hHUGFMQ8', 'di7HHgDVU3', 'WPhHuZdIF0', 'jecHQtuy81', 'S8EHnCMkGg', 'Dispose', 'LaqemtE7ag', 'lEmeWMFu5u', 'wvpeg8N1fq' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, h3TbBgPKWJM3k3GmXI.cs | High entropy of concatenated method names: 'Bv0Hj9P4vN', 'PoCHI7bXh9', 'tP0HorBdxk', 'IZFHkKqDSB', 'UFwH4dBZ5o', 'ogmHfMfU7I', 'tblHCCM6eU', 'nwbHBP7FxE', 'SsyHNnx5Wn', 'DvtHYPC36J' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, oxFBU42wJTr2UTVcBS.cs | High entropy of concatenated method names: 'gdZWZTamEN', 'cYxWGfDJ6P', 'rqsWvqG85K', 'Q24WMioCkT', 'rNOW5G1gr6', 'jSLWrW6foE', 'SR2WsFrbym', 'hWXW8tYt4w', 'JI0WPWFWqv', 'lU8Wh0W6ir' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, qGWQwo3dZPjlkLfaXEb.cs | High entropy of concatenated method names: 'YktuhfmIYi', 'LD9uzApOq9', 'e62bXRuxUF', 'wm5bICyysQdvmS0Q4XK', 'z8lOOUyLLHyT7DMV13X', 'bHiac7yXndI6kdjUemP', 'hl7PP7yYada2wJVpExC' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, UFuoQeCdlpIA3uNJJl.cs | High entropy of concatenated method names: 'vDVamV7Xnr', 'vJOag5ovPb', 'JaoapdFwQR', 'D7QphduMc9', 'I2ipzGUjRU', 'gt4aXushGK', 'gITa3pQxCc', 'UwGaKQRs84', 'acQadBXrkB', 'SoUaRkv0wZ' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, fRMpebh3HnJSGfKfL5.cs | High entropy of concatenated method names: 'ALF7gxHoIM', 'aPJ7DUGyTh', 'zHi7pDRhFN', 'KDK7aqetw2', 'dLQ7Hk0QyX', 'Sg079EB4Xj', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, qBd4H5tgmR5ZnW4Vei.cs | High entropy of concatenated method names: 'SutDAJlYvu', 'ROiDTD7a6p', 'mTmgouYxdA', 'L8LgkWOIJ0', 'W3Ag4urpy0', 'DrNgfaG3pJ', 'YTHgCpg8YQ', 'DeXgBstkRy', 'pSJgNqq9kK', 'CsugYjNTct' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, EuOpUCriLBxCLqaAMU.cs | High entropy of concatenated method names: 'vOfU8JiVtS', 'kejUh5P7hq', 'SsmeXP6x2t', 'QJie3NWrSU', 'GF1USGkmOm', 'WiyUJ3iYo2', 'WsjULLBDQN', 'kxpUZuaE8e', 'h6cUGQhmVq', 'hBvUvt1s7r' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, CmxdKqWHRvJdY9P2C6.cs | High entropy of concatenated method names: 'Dispose', 'dsu3PnRk5t', 'rm3KI9Ogld', 'Qc9iynxKxx', 'xPb3h5Y0G1', 'lEh3zmDCB4', 'ProcessDialogKey', 'BLgKX3TbBg', 'bWJK3M3k3G', 'fXIKKmRMpe' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, KxSlmh3RWIExw3kFaGD.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z08bHsNTZt', 'ecEb7Gibds', 'qkVbu8Vsq1', 'yOpbbc5rbG', 'kJ0bQvpgRT', 'eCebiuG1RS', 'ywtbnw3DD6' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, xGWxxQzs6QMPuKRFe2.cs | High entropy of concatenated method names: 'Aa47OyMdV0', 'LFy72Jn1d0', 'K3o7xmxHL9', 'n0x7jyVL10', 'TvY7ICrcs6', 'TgC7kWqNRO', 'DvN74adREW', 'pbF7nn2tWa', 'QTQ7wEuCWn', 'VlA7FUj0xI' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, biOSFH33IeY62QRJA5u.cs | High entropy of concatenated method names: 'QlJ7hp51tX', 'MG57zf7uE8', 'JcnuXUOOQD', 'fA8u3qOCi4', 'FSLuKS6IhR', 'rOoudh4wZt', 'ITfuRayqui', 'inZulFFGL1', 'jZNumyFrVi', 'b7UuWxWnYF' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, G5HkYS3K1F7W131Parx.cs | High entropy of concatenated method names: 'ToString', 'VWUu29M9nH', 'MVbuxhGMUF', 'iJ8utawXTD', 'JRLujRBLdW', 'qDkuIy5ybl', 'jxiuo8mK8k', 'wY9ukYXNFp', 'P7KdVQyQjg5MX7td4nQ', 'tHGhUAyF7lc1PN7P3jK' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, qYwR0TMDtDIN8pqpVU.cs | High entropy of concatenated method names: 'BD7U66QRgG', 'nAxUqfollF', 'ToString', 'wlwUm64e64', 'mhHUWUVW0m', 'zHcUgC0Lhx', 'rNTUDVxSBj', 'FU6UpWpA6U', 'FBeUas9IZb', 'a0oU99NcCK' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, LXtXutRj3L0weLOGZY.cs | High entropy of concatenated method names: 'F8c3axFBU4', 'xJT39r2UTV', 'eGN364ahiv', 'us03qOUBd4', 'g4V3VeivHo', 'mSo31uYakG', 'yxG1MyehurFOIaCjcr', 'QK6o1mHaIraxp3BFvG', 'Fv933fjTu5', 'jX53dwsoay' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, UeK7EHGFSG5neVbdSw.cs | High entropy of concatenated method names: 'nbNVs063IM', 'XPBV8TMQUC', 'dUEVPT2A0j', 'ht3VhZ13r1', 'p525tGkInunKOMT2f6S', 'QHQbV4kYEaXYvcxiYYR', 'bClmjgknsESuy7o594T' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, mKU4ufKcuQsUByve7r.cs | High entropy of concatenated method names: 'VItECekKP', 'IqC0W8elS', 'UpHOa6EJf', 'P4NTtkGB1', 'IY6xDZZ3I', 'fIKtwLipq', 'w5Etjeu7NULWdSieki', 'RvXf0NPgYG12aGGDNY', 'f4ae92gPt', 'JYY7gfda3' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, HdUXMlxGN4ahivbs0O.cs | High entropy of concatenated method names: 'uhSg0nX4tU', 'uhdgOdZPyk', 'xR2g2QEytr', 'YUtgxoWcVD', 'L7PgVvKeVs', 'XN5g1erWgM', 'CFpgUHOUVG', 'y7yge176mP', 'DaMgHipFIa', 'XNXg73fxNs' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, YBBGBdLdRgRLbm4owH.cs | High entropy of concatenated method names: 'xJnc2OJVPr', 'HGMcxjHCrF', 'FKEcjp1Lfs', 'bDucIDDW7G', 'lDxckPRHCp', 'Kfvc47gPNf', 'GwDcC0Wj3c', 'bekcBNIuZy', 'a3ocYmRbPR', 'tpEcSZ6mhr' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, SHo6SojuYakG6IgwZL.cs | High entropy of concatenated method names: 'KXOpl6bCye', 'd9ypW5gmQX', 'gyWpDflitr', 'qZLpap8reC', 'Xxcp9K9coy', 'kBwD5BnHfP', 'rftDrFd5BB', 'hhTDsv73gI', 'sEtD8aUT80', 'NJ7DPla2TT' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, qyyPq296Qkh0EGin1j.cs | High entropy of concatenated method names: 'euPdl7mcaD', 'GFpdm8cMPX', 'ARXdWkGCMc', 'J1xdglQem5', 'o1rdDC7DXT', 'GfCdpo0y6C', 'TqadaJe7Qc', 'C0ad9cnMHI', 'aXfdy2Hn7t', 'AVvd6CwsdW' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, whT9VAvWrWdOTj3EWO.cs | High entropy of concatenated method names: 'ToString', 'HV41S9wE0x', 'zBN1IqjnDN', 'aBO1otoC4M', 'Plr1ko0y1i', 'IZB14hmjai', 'j2w1fjqtJA', 'M9a1CtUvUE', 'BbA1BLpqst', 'ogf1Nkre7A' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, Ko28UW3XlevF8QFhQ37.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'D8F7SHgxen', 'lke7Jp3es7', 'U1G7LW9wfa', 'JxR7Z5LvDG', 'Eqe7G2j9V1', 'wMK7vU1pZh', 'Mlo7MJmBYk' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, c0npjGZVC8QoekSSiE.cs | High entropy of concatenated method names: 'oZ7VYCnT0c', 'JNAVJ2y6N2', 'BTqVZ9vKHe', 'rroVGn95O6', 'DtiVIgGoL5', 'l39VoG98lM', 'fLoVkVeIkQ', 'WcPV4I0S9L', 'mTyVffQVVl', 'muOVCunoqX' |
Source: 0.2.ljMiHZ8MwZ.exe.432ec78.3.raw.unpack, bD37EoNqtrph9p0XKi.cs | High entropy of concatenated method names: 'ELqaw0Q2pj', 'sKiaFEIPPu', 'ahvaEBSRyN', 'YSVa0Z019T', 'CtZaAwGRaF', 'hXiaOM8Ifk', 'cQaaTGXP8U', 'z1Ha2oD9Jw', 'BdPax0uMoO', 'yk7at26fk1' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, fveyHcscgRsunRk5tw.cs | High entropy of concatenated method names: 'OdIHVklGB7', 'A0hHUGFMQ8', 'di7HHgDVU3', 'WPhHuZdIF0', 'jecHQtuy81', 'S8EHnCMkGg', 'Dispose', 'LaqemtE7ag', 'lEmeWMFu5u', 'wvpeg8N1fq' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, h3TbBgPKWJM3k3GmXI.cs | High entropy of concatenated method names: 'Bv0Hj9P4vN', 'PoCHI7bXh9', 'tP0HorBdxk', 'IZFHkKqDSB', 'UFwH4dBZ5o', 'ogmHfMfU7I', 'tblHCCM6eU', 'nwbHBP7FxE', 'SsyHNnx5Wn', 'DvtHYPC36J' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, oxFBU42wJTr2UTVcBS.cs | High entropy of concatenated method names: 'gdZWZTamEN', 'cYxWGfDJ6P', 'rqsWvqG85K', 'Q24WMioCkT', 'rNOW5G1gr6', 'jSLWrW6foE', 'SR2WsFrbym', 'hWXW8tYt4w', 'JI0WPWFWqv', 'lU8Wh0W6ir' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, qGWQwo3dZPjlkLfaXEb.cs | High entropy of concatenated method names: 'YktuhfmIYi', 'LD9uzApOq9', 'e62bXRuxUF', 'wm5bICyysQdvmS0Q4XK', 'z8lOOUyLLHyT7DMV13X', 'bHiac7yXndI6kdjUemP', 'hl7PP7yYada2wJVpExC' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, UFuoQeCdlpIA3uNJJl.cs | High entropy of concatenated method names: 'vDVamV7Xnr', 'vJOag5ovPb', 'JaoapdFwQR', 'D7QphduMc9', 'I2ipzGUjRU', 'gt4aXushGK', 'gITa3pQxCc', 'UwGaKQRs84', 'acQadBXrkB', 'SoUaRkv0wZ' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, fRMpebh3HnJSGfKfL5.cs | High entropy of concatenated method names: 'ALF7gxHoIM', 'aPJ7DUGyTh', 'zHi7pDRhFN', 'KDK7aqetw2', 'dLQ7Hk0QyX', 'Sg079EB4Xj', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, qBd4H5tgmR5ZnW4Vei.cs | High entropy of concatenated method names: 'SutDAJlYvu', 'ROiDTD7a6p', 'mTmgouYxdA', 'L8LgkWOIJ0', 'W3Ag4urpy0', 'DrNgfaG3pJ', 'YTHgCpg8YQ', 'DeXgBstkRy', 'pSJgNqq9kK', 'CsugYjNTct' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, EuOpUCriLBxCLqaAMU.cs | High entropy of concatenated method names: 'vOfU8JiVtS', 'kejUh5P7hq', 'SsmeXP6x2t', 'QJie3NWrSU', 'GF1USGkmOm', 'WiyUJ3iYo2', 'WsjULLBDQN', 'kxpUZuaE8e', 'h6cUGQhmVq', 'hBvUvt1s7r' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, CmxdKqWHRvJdY9P2C6.cs | High entropy of concatenated method names: 'Dispose', 'dsu3PnRk5t', 'rm3KI9Ogld', 'Qc9iynxKxx', 'xPb3h5Y0G1', 'lEh3zmDCB4', 'ProcessDialogKey', 'BLgKX3TbBg', 'bWJK3M3k3G', 'fXIKKmRMpe' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, KxSlmh3RWIExw3kFaGD.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z08bHsNTZt', 'ecEb7Gibds', 'qkVbu8Vsq1', 'yOpbbc5rbG', 'kJ0bQvpgRT', 'eCebiuG1RS', 'ywtbnw3DD6' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, xGWxxQzs6QMPuKRFe2.cs | High entropy of concatenated method names: 'Aa47OyMdV0', 'LFy72Jn1d0', 'K3o7xmxHL9', 'n0x7jyVL10', 'TvY7ICrcs6', 'TgC7kWqNRO', 'DvN74adREW', 'pbF7nn2tWa', 'QTQ7wEuCWn', 'VlA7FUj0xI' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, biOSFH33IeY62QRJA5u.cs | High entropy of concatenated method names: 'QlJ7hp51tX', 'MG57zf7uE8', 'JcnuXUOOQD', 'fA8u3qOCi4', 'FSLuKS6IhR', 'rOoudh4wZt', 'ITfuRayqui', 'inZulFFGL1', 'jZNumyFrVi', 'b7UuWxWnYF' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, G5HkYS3K1F7W131Parx.cs | High entropy of concatenated method names: 'ToString', 'VWUu29M9nH', 'MVbuxhGMUF', 'iJ8utawXTD', 'JRLujRBLdW', 'qDkuIy5ybl', 'jxiuo8mK8k', 'wY9ukYXNFp', 'P7KdVQyQjg5MX7td4nQ', 'tHGhUAyF7lc1PN7P3jK' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, qYwR0TMDtDIN8pqpVU.cs | High entropy of concatenated method names: 'BD7U66QRgG', 'nAxUqfollF', 'ToString', 'wlwUm64e64', 'mhHUWUVW0m', 'zHcUgC0Lhx', 'rNTUDVxSBj', 'FU6UpWpA6U', 'FBeUas9IZb', 'a0oU99NcCK' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, LXtXutRj3L0weLOGZY.cs | High entropy of concatenated method names: 'F8c3axFBU4', 'xJT39r2UTV', 'eGN364ahiv', 'us03qOUBd4', 'g4V3VeivHo', 'mSo31uYakG', 'yxG1MyehurFOIaCjcr', 'QK6o1mHaIraxp3BFvG', 'Fv933fjTu5', 'jX53dwsoay' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, UeK7EHGFSG5neVbdSw.cs | High entropy of concatenated method names: 'nbNVs063IM', 'XPBV8TMQUC', 'dUEVPT2A0j', 'ht3VhZ13r1', 'p525tGkInunKOMT2f6S', 'QHQbV4kYEaXYvcxiYYR', 'bClmjgknsESuy7o594T' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, mKU4ufKcuQsUByve7r.cs | High entropy of concatenated method names: 'VItECekKP', 'IqC0W8elS', 'UpHOa6EJf', 'P4NTtkGB1', 'IY6xDZZ3I', 'fIKtwLipq', 'w5Etjeu7NULWdSieki', 'RvXf0NPgYG12aGGDNY', 'f4ae92gPt', 'JYY7gfda3' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, HdUXMlxGN4ahivbs0O.cs | High entropy of concatenated method names: 'uhSg0nX4tU', 'uhdgOdZPyk', 'xR2g2QEytr', 'YUtgxoWcVD', 'L7PgVvKeVs', 'XN5g1erWgM', 'CFpgUHOUVG', 'y7yge176mP', 'DaMgHipFIa', 'XNXg73fxNs' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, YBBGBdLdRgRLbm4owH.cs | High entropy of concatenated method names: 'xJnc2OJVPr', 'HGMcxjHCrF', 'FKEcjp1Lfs', 'bDucIDDW7G', 'lDxckPRHCp', 'Kfvc47gPNf', 'GwDcC0Wj3c', 'bekcBNIuZy', 'a3ocYmRbPR', 'tpEcSZ6mhr' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, SHo6SojuYakG6IgwZL.cs | High entropy of concatenated method names: 'KXOpl6bCye', 'd9ypW5gmQX', 'gyWpDflitr', 'qZLpap8reC', 'Xxcp9K9coy', 'kBwD5BnHfP', 'rftDrFd5BB', 'hhTDsv73gI', 'sEtD8aUT80', 'NJ7DPla2TT' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, qyyPq296Qkh0EGin1j.cs | High entropy of concatenated method names: 'euPdl7mcaD', 'GFpdm8cMPX', 'ARXdWkGCMc', 'J1xdglQem5', 'o1rdDC7DXT', 'GfCdpo0y6C', 'TqadaJe7Qc', 'C0ad9cnMHI', 'aXfdy2Hn7t', 'AVvd6CwsdW' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, whT9VAvWrWdOTj3EWO.cs | High entropy of concatenated method names: 'ToString', 'HV41S9wE0x', 'zBN1IqjnDN', 'aBO1otoC4M', 'Plr1ko0y1i', 'IZB14hmjai', 'j2w1fjqtJA', 'M9a1CtUvUE', 'BbA1BLpqst', 'ogf1Nkre7A' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, Ko28UW3XlevF8QFhQ37.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'D8F7SHgxen', 'lke7Jp3es7', 'U1G7LW9wfa', 'JxR7Z5LvDG', 'Eqe7G2j9V1', 'wMK7vU1pZh', 'Mlo7MJmBYk' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, c0npjGZVC8QoekSSiE.cs | High entropy of concatenated method names: 'oZ7VYCnT0c', 'JNAVJ2y6N2', 'BTqVZ9vKHe', 'rroVGn95O6', 'DtiVIgGoL5', 'l39VoG98lM', 'fLoVkVeIkQ', 'WcPV4I0S9L', 'mTyVffQVVl', 'muOVCunoqX' |
Source: 0.2.ljMiHZ8MwZ.exe.42d2a58.0.raw.unpack, bD37EoNqtrph9p0XKi.cs | High entropy of concatenated method names: 'ELqaw0Q2pj', 'sKiaFEIPPu', 'ahvaEBSRyN', 'YSVa0Z019T', 'CtZaAwGRaF', 'hXiaOM8Ifk', 'cQaaTGXP8U', 'z1Ha2oD9Jw', 'BdPax0uMoO', 'yk7at26fk1' |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Users\user\Desktop\ljMiHZ8MwZ.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Users\user\Desktop\ljMiHZ8MwZ.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ljMiHZ8MwZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation | Jump to behavior |