Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Cookies |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \Default\Login Data |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \Login Data |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: //setting[@name='Password']/value |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Password : |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Software\Martin Prikryl\WinSCP 2\Sessions |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: SMTP Email Address |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: NNTP Email Address |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Email |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: HTTPMail User Name |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: HTTPMail Server |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^([a-zA-Z0-9_\-\.]+)@([a-zA-Z0-9_\-\.]+)\.([a-zA-Z]{2,5})$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(?!:\/\/)([a-zA-Z0-9-_]+\.)[a-zA-Z0-9][a-zA-Z0-9-_]+\.[a-zA-Z]{2,11}?$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Password |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^3[47][0-9]{13}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(6541|6556)[0-9]{12}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^389[0-9]{11}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^3(?:0[0-5]|[68][0-9])[0-9]{11}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ViSAg4tw{_C~N2DxWG |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(?:2131|1800|35\\d{3})\\d{11}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^9[0-9]{15}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(6304|6706|6709|6771)[0-9]{12,15}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(5018|5020|5038|6304|6759|6761|6763)[0-9]{8,15}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Mastercard |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(6334|6767)[0-9]{12}|(6334|6767)[0-9]{14}|(6334|6767)[0-9]{15}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(4903|4905|4911|4936|6333|6759)[0-9]{12}|(4903|4905|4911|4936|6333|6759)[0-9]{14}|(4903|4905|4911|4936|6333|6759)[0-9]{15}|564182[0-9]{10}|564182[0-9]{12}|564182[0-9]{13}|633110[0-9]{10}|633110[0-9]{12}|633110[0-9]{13}$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(62[0-9]{14,17})$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Visa Card |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: ^(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14})$ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Visa Master Card |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \logins.json |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \signons.sqlite |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Foxmail.exe |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: mail\ |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \Accounts\Account.rec0 |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: \AccCfg\Accounts.tdat |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: EnableSignature |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: Application : FoxMail |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: logins |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: encryptedPassword |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: jscottt349@gmail.com |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/sendusing |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpauthenticate |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpserver |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpserverport |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpusessl |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/sendusername |
Source: 8.2.UNTKRsD.exe.44441a8.3.raw.unpack | String decryptor: http://schemas.microsoft.com/cdo/configuration/sendpassword |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_014E95A0 | 0_2_014E95A0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_05F668E0 | 0_2_05F668E0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_05F668D0 | 0_2_05F668D0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E6318 | 0_2_070E6318 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E73D1 | 0_2_070E73D1 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E2240 | 0_2_070E2240 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E01F8 | 0_2_070E01F8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E0D38 | 0_2_070E0D38 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5D68 | 0_2_070E5D68 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E7C80 | 0_2_070E7C80 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5938 | 0_2_070E5938 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5730 | 0_2_070E5730 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5740 | 0_2_070E5740 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E6751 | 0_2_070E6751 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E6760 | 0_2_070E6760 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070EF638 | 0_2_070EF638 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E1490 | 0_2_070E1490 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E54B8 | 0_2_070E54B8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E54C8 | 0_2_070E54C8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E6309 | 0_2_070E6309 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070EF200 | 0_2_070EF200 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E8260 | 0_2_070E8260 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5298 | 0_2_070E5298 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E52A8 | 0_2_070E52A8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E4058 | 0_2_070E4058 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E4068 | 0_2_070E4068 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5FB0 | 0_2_070E5FB0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5FC0 | 0_2_070E5FC0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E0D06 | 0_2_070E0D06 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070EEDC8 | 0_2_070EEDC8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E4C09 | 0_2_070E4C09 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E4C18 | 0_2_070E4C18 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E6C10 | 0_2_070E6C10 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E0CA9 | 0_2_070E0CA9 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E1CB0 | 0_2_070E1CB0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E5929 | 0_2_070E5929 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_070E18D8 | 0_2_070E18D8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_075D6AB0 | 0_2_075D6AB0 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_075D0EE8 | 0_2_075D0EE8 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Code function: 0_2_075D18E8 | 0_2_075D18E8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_048F5D01 | 8_2_048F5D01 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_048F0EE8 | 8_2_048F0EE8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_048F18E8 | 8_2_048F18E8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D12260 | 8_2_06D12260 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D10208 | 8_2_06D10208 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D173E0 | 8_2_06D173E0 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16318 | 8_2_06D16318 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D17C90 | 8_2_06D17C90 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15D78 | 8_2_06D15D78 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D10D38 | 8_2_06D10D38 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15938 | 8_2_06D15938 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D1F638 | 8_2_06D1F638 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16751 | 8_2_06D16751 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15740 | 8_2_06D15740 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16760 | 8_2_06D16760 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15730 | 8_2_06D15730 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D154C8 | 8_2_06D154C8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D11490 | 8_2_06D11490 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D154B8 | 8_2_06D154B8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D114A0 | 8_2_06D114A0 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15298 | 8_2_06D15298 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D152A8 | 8_2_06D152A8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D12240 | 8_2_06D12240 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D18270 | 8_2_06D18270 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D18260 | 8_2_06D18260 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D1F200 | 8_2_06D1F200 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D173D1 | 8_2_06D173D1 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16309 | 8_2_06D16309 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D14058 | 8_2_06D14058 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D14068 | 8_2_06D14068 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D101F8 | 8_2_06D101F8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15FC0 | 8_2_06D15FC0 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15FB0 | 8_2_06D15FB0 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D17C80 | 8_2_06D17C80 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D11CB0 | 8_2_06D11CB0 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D10CA9 | 8_2_06D10CA9 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16C10 | 8_2_06D16C10 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D14C18 | 8_2_06D14C18 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D14C09 | 8_2_06D14C09 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D16C20 | 8_2_06D16C20 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D1EDC8 | 8_2_06D1EDC8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15D69 | 8_2_06D15D69 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D10D07 | 8_2_06D10D07 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D118D8 | 8_2_06D118D8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D118E8 | 8_2_06D118E8 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 8_2_06D15929 | 8_2_06D15929 |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Code function: 12_2_00426E80 | 12_2_00426E80 |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: winsqlite3.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: winsqlite3.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: esscli.dll | |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, yBOQlXeQEM3H2iImIq.cs | High entropy of concatenated method names: 'i61SCOB86F', 'c9ISjMGL1i', 'S0IvnfIKNo', 'iZZv27vxXE', 'ilOvOLyy1a', 'FBFvZayj1j', 'J0IvyVlrp3', 'DkqvmTMpuX', 'AKlvfXMGgt', 'vTDv5yIKtt' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, HHMxicrcplcPFa0Uat.cs | High entropy of concatenated method names: 'yIvcYtQwyV', 'yMicgwlsgC', 'PaFUwKmKt7', 'ybMUtuwS8H', 'B8vcEFgOb3', 'iMBc8B3UJJ', 'Ea0cNfDR9W', 'Tk9cFkdy3k', 'eC8csDRCVx', 'r0DcAh9AOL' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, kYiwP0hu8ikcda3vHI.cs | High entropy of concatenated method names: 'I8x1UY0rQ', 'XBPbmnGVD', 'xArR7Hb11', 'yv8j7MdWh', 'nmTppdGEe', 'caoeTP6aP', 'bHd0CeJdhp8ELgKHYr', 's2wLUxiZ4BO3v8tPUi', 'jTsUrUmTV', 'DPEXh8LLC' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, A5LcZot3BTgauTK284i.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'NybV0bpovd', 'MmUVXDvMhK', 'fQAVitKZmm', 'wkZVVKMUx8', 'VGlVWfRj43', 'TXhVH9cOAU', 'm2MVa7MfeQ' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, KbGYW64TQtPknvF7f1.cs | High entropy of concatenated method names: 'Fk7xFMOFRa', 'a9txsjfBUw', 'sfRxAgnrky', 'b0Kx9wq7AQ', 'Oufxdpa8os', 'nvJxr3xMLD', 'XBxxQOupUc', 'bi8xYNJRbQ', 'L7IxDvAHwS', 'RxExgsm93Q' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, bsqTdhfopvhHVvpu32.cs | High entropy of concatenated method names: 'KNnBPM5L25', 'osOBGrw7f9', 'fwQB1tgdPd', 'cshBbtMBFs', 'nGvBCYOJ0w', 'f06BRsN28e', 'cRgBjkMoIL', 'bb7B4JVmaJ', 'sFSBpcKujk', 'hBoBeJfN0u' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, TfwZiPAo7ejIb1yYkD.cs | High entropy of concatenated method names: 'ToString', 'sASlEDGbcc', 'tAilK8fpeS', 'wb0lnZI9De', 'zCul2MHohw', 'SrrlO9FhLb', 'ieclZUECjT', 'L7Olyhfpus', 'S7GlmS0DtT', 'VqLlfn9Jdc' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, z1kwL7ttjx6EtnXEHld.cs | High entropy of concatenated method names: 'hTkXg4bGO3', 'mwDXzWrnVJ', 'ynkiwL4jpv', 'l8iiteUkCG', 'xAbihE0cwI', 'scIiMxjxQs', 'CcWi32V9Fa', 'WLliTgRlC0', 'GNjiu3ndPf', 'TS4ixnrXEQ' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, GtZCd7FDvBUjg9efA5.cs | High entropy of concatenated method names: 'LXb75aWyKH', 'OCE78Xo57J', 'fZ27FpVeZj', 'ODL7sH2bGZ', 'wh87Kbyr3W', 'UTc7nrRH3o', 'bIh72Z0GgB', 'fBR7O3qmD6', 'Bmf7Z70HgB', 'e2B7y6W59Z' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, WUKNWW3y7PNwVoYhy7.cs | High entropy of concatenated method names: 'mXZtBbGYW6', 'eQttqPknvF', 'PGrtJT387V', 'SaQtkHGBOQ', 'tImt7Iqil6', 'kg2tlAKrhf', 'G2bNW3yHd5wQ28nDHS', 'gFGY7Gavr4aYn5yoUZ', 'pwuttGs3WL', 'hiytMseX06' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, KesChXzAOdWqMcglng.cs | High entropy of concatenated method names: 'QPVXRBubZM', 'LfAX4sMPFe', 'oy6XpLxkhG', 'G2XX6IaGiP', 'u7YXKx1jeS', 'r57X2SugoB', 'SZWXOYHfJc', 'jd3XaQMcRi', 'exPXP1AISR', 'rK6XGluetX' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, zcscPeywLO41sBRm1K.cs | High entropy of concatenated method names: 'xXGBufDF52', 'qgpBvWXx8Y', 'Y3kBo5CVbC', 'USpogc5990', 'iiRozyxaQi', 'FB0Bw6Otld', 'oFMBtXvCId', 'MInBhgH0Af', 'c4sBMm5fp3', 'CKwB3dfrCd' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, M5jMfMvcjF1sChF1AZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4IhDtntpW', 'Gbthgpl4GK', 'lUXhzauq1O', 'KF0MwGB4XX', 'nLhMtj1sLE', 'Ae2MhmZdTY', 'cubMMa5NqV', 'cKZAJQovBf2rG5My7hx' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, tl6qg26AKrhfKSSE69.cs | High entropy of concatenated method names: 'zYnoTJrlp2', 'bR7ox2wKu3', 'qkJoSga4PH', 'b5UoBeXyo8', 'eZ9oqiVZAq', 'jc0Sd5fn8x', 'tLrSrOiGci', 'DUBSQkRtmG', 'sfRSYGXwWE', 'MKWSD2Cr8k' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, mE3x5T9Qlh7UxTOYtE.cs | High entropy of concatenated method names: 'Bv4cJPrQjV', 'LWLckFsTNp', 'ToString', 'QgGcu93xX9', 'FcicxrBDkt', 'qI3cvPhsYl', 'PSFcSYID8P', 'zSQcoC00x8', 'HLEcBp7gV9', 'Xb9cqrsUw7' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, PAtPNyDv6E2pKbHO0f.cs | High entropy of concatenated method names: 'fUP06dulS9', 'lRo0KOl7SG', 'E7o0nJRTDQ', 'hZr02wsJvx', 'M9o0OHFtNv', 'amr0ZIoDry', 'TYw0ysSZdh', 'AyC0mDEh5F', 'd0e0fNhqQP', 'RvM05iwiBX' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, UUrS32NDkv1vdk1x5k.cs | High entropy of concatenated method names: 'rkrL4V6UoH', 'CbPLpJEcsn', 'YmML6ajkGI', 'BCeLK0lGTj', 'yagL2ZDYWY', 'eqsLO6Flul', 'A9cLygNW03', 'H4GLmNJeB7', 'aU1L56nJQL', 'B1aLExDEk9' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, PNmVxvtwn2Jl6aGCle5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'xUmXEUVCMb', 'dDaX8KCWOR', 'aftXNjLGrr', 'UnfXF08T0Q', 'sXmXshMQ28', 'H9dXAqTuTr', 'DycX9298Uf' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, hI2dV4qa0vWmOJFbgT.cs | High entropy of concatenated method names: 'DTIMTXWWjc', 'Ri5MudsRqV', 'dIoMxq8erg', 'FOJMvCUQJZ', 'vWrMS9T1Oj', 'pBLMo1wqeX', 'E7BMBfR3jk', 'D5XMqDAx9J', 'ITWMIckv0w', 'NTfMJNJfqG' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, iFJ71Rxs79e7aeM5Ur.cs | High entropy of concatenated method names: 'Dispose', 'kHftDM2ZRD', 'IKGhK5qXvU', 'kxaQs6KNTy', 'UbXtgpmvRK', 'bcttzTv3Ix', 'ProcessDialogKey', 'EUNhwAtPNy', 'h6Eht2pKbH', 'J0fhhHEWe2' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, JvB0ZNpGrT387VAaQH.cs | High entropy of concatenated method names: 'TBmvbQt99B', 'vubvRcDZAr', 'z4kv43TSCL', 'K2YvpXe84F', 'xEGv7fEyRD', 'sA8vlpR7Ot', 'f8KvcdVu6W', 'fGovUsakZ0', 'kUPv0g6aYj', 'P0KvXjoOLn' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, vEWe2xgYyqEmZLKkkM.cs | High entropy of concatenated method names: 'xCvXvoEQSp', 'PNpXSgtgNY', 'oT8XoV02gT', 'RqoXBHAoiP', 'EUtX03lyS5', 'yBgXqbbnZ7', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.payment slip______________________pdf.exe.4a70e98.1.raw.unpack, bN9Yf3QHRIHfM2ZRDd.cs | High entropy of concatenated method names: 'va707hDpWX', 'EUc0cMNB9k', 'xhB00ufce4', 'oki0iDI9f3', 'OGN0WWUMUe', 'jfk0ayaZXV', 'Dispose', 'L6WUue9er9', 'BmBUxBbwGx', 'TasUvS7CWT' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, yBOQlXeQEM3H2iImIq.cs | High entropy of concatenated method names: 'i61SCOB86F', 'c9ISjMGL1i', 'S0IvnfIKNo', 'iZZv27vxXE', 'ilOvOLyy1a', 'FBFvZayj1j', 'J0IvyVlrp3', 'DkqvmTMpuX', 'AKlvfXMGgt', 'vTDv5yIKtt' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, HHMxicrcplcPFa0Uat.cs | High entropy of concatenated method names: 'yIvcYtQwyV', 'yMicgwlsgC', 'PaFUwKmKt7', 'ybMUtuwS8H', 'B8vcEFgOb3', 'iMBc8B3UJJ', 'Ea0cNfDR9W', 'Tk9cFkdy3k', 'eC8csDRCVx', 'r0DcAh9AOL' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, kYiwP0hu8ikcda3vHI.cs | High entropy of concatenated method names: 'I8x1UY0rQ', 'XBPbmnGVD', 'xArR7Hb11', 'yv8j7MdWh', 'nmTppdGEe', 'caoeTP6aP', 'bHd0CeJdhp8ELgKHYr', 's2wLUxiZ4BO3v8tPUi', 'jTsUrUmTV', 'DPEXh8LLC' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, A5LcZot3BTgauTK284i.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'NybV0bpovd', 'MmUVXDvMhK', 'fQAVitKZmm', 'wkZVVKMUx8', 'VGlVWfRj43', 'TXhVH9cOAU', 'm2MVa7MfeQ' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, KbGYW64TQtPknvF7f1.cs | High entropy of concatenated method names: 'Fk7xFMOFRa', 'a9txsjfBUw', 'sfRxAgnrky', 'b0Kx9wq7AQ', 'Oufxdpa8os', 'nvJxr3xMLD', 'XBxxQOupUc', 'bi8xYNJRbQ', 'L7IxDvAHwS', 'RxExgsm93Q' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, bsqTdhfopvhHVvpu32.cs | High entropy of concatenated method names: 'KNnBPM5L25', 'osOBGrw7f9', 'fwQB1tgdPd', 'cshBbtMBFs', 'nGvBCYOJ0w', 'f06BRsN28e', 'cRgBjkMoIL', 'bb7B4JVmaJ', 'sFSBpcKujk', 'hBoBeJfN0u' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, TfwZiPAo7ejIb1yYkD.cs | High entropy of concatenated method names: 'ToString', 'sASlEDGbcc', 'tAilK8fpeS', 'wb0lnZI9De', 'zCul2MHohw', 'SrrlO9FhLb', 'ieclZUECjT', 'L7Olyhfpus', 'S7GlmS0DtT', 'VqLlfn9Jdc' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, z1kwL7ttjx6EtnXEHld.cs | High entropy of concatenated method names: 'hTkXg4bGO3', 'mwDXzWrnVJ', 'ynkiwL4jpv', 'l8iiteUkCG', 'xAbihE0cwI', 'scIiMxjxQs', 'CcWi32V9Fa', 'WLliTgRlC0', 'GNjiu3ndPf', 'TS4ixnrXEQ' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, GtZCd7FDvBUjg9efA5.cs | High entropy of concatenated method names: 'LXb75aWyKH', 'OCE78Xo57J', 'fZ27FpVeZj', 'ODL7sH2bGZ', 'wh87Kbyr3W', 'UTc7nrRH3o', 'bIh72Z0GgB', 'fBR7O3qmD6', 'Bmf7Z70HgB', 'e2B7y6W59Z' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, WUKNWW3y7PNwVoYhy7.cs | High entropy of concatenated method names: 'mXZtBbGYW6', 'eQttqPknvF', 'PGrtJT387V', 'SaQtkHGBOQ', 'tImt7Iqil6', 'kg2tlAKrhf', 'G2bNW3yHd5wQ28nDHS', 'gFGY7Gavr4aYn5yoUZ', 'pwuttGs3WL', 'hiytMseX06' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, KesChXzAOdWqMcglng.cs | High entropy of concatenated method names: 'QPVXRBubZM', 'LfAX4sMPFe', 'oy6XpLxkhG', 'G2XX6IaGiP', 'u7YXKx1jeS', 'r57X2SugoB', 'SZWXOYHfJc', 'jd3XaQMcRi', 'exPXP1AISR', 'rK6XGluetX' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, zcscPeywLO41sBRm1K.cs | High entropy of concatenated method names: 'xXGBufDF52', 'qgpBvWXx8Y', 'Y3kBo5CVbC', 'USpogc5990', 'iiRozyxaQi', 'FB0Bw6Otld', 'oFMBtXvCId', 'MInBhgH0Af', 'c4sBMm5fp3', 'CKwB3dfrCd' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, M5jMfMvcjF1sChF1AZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4IhDtntpW', 'Gbthgpl4GK', 'lUXhzauq1O', 'KF0MwGB4XX', 'nLhMtj1sLE', 'Ae2MhmZdTY', 'cubMMa5NqV', 'cKZAJQovBf2rG5My7hx' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, tl6qg26AKrhfKSSE69.cs | High entropy of concatenated method names: 'zYnoTJrlp2', 'bR7ox2wKu3', 'qkJoSga4PH', 'b5UoBeXyo8', 'eZ9oqiVZAq', 'jc0Sd5fn8x', 'tLrSrOiGci', 'DUBSQkRtmG', 'sfRSYGXwWE', 'MKWSD2Cr8k' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, mE3x5T9Qlh7UxTOYtE.cs | High entropy of concatenated method names: 'Bv4cJPrQjV', 'LWLckFsTNp', 'ToString', 'QgGcu93xX9', 'FcicxrBDkt', 'qI3cvPhsYl', 'PSFcSYID8P', 'zSQcoC00x8', 'HLEcBp7gV9', 'Xb9cqrsUw7' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, PAtPNyDv6E2pKbHO0f.cs | High entropy of concatenated method names: 'fUP06dulS9', 'lRo0KOl7SG', 'E7o0nJRTDQ', 'hZr02wsJvx', 'M9o0OHFtNv', 'amr0ZIoDry', 'TYw0ysSZdh', 'AyC0mDEh5F', 'd0e0fNhqQP', 'RvM05iwiBX' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, UUrS32NDkv1vdk1x5k.cs | High entropy of concatenated method names: 'rkrL4V6UoH', 'CbPLpJEcsn', 'YmML6ajkGI', 'BCeLK0lGTj', 'yagL2ZDYWY', 'eqsLO6Flul', 'A9cLygNW03', 'H4GLmNJeB7', 'aU1L56nJQL', 'B1aLExDEk9' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, PNmVxvtwn2Jl6aGCle5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'xUmXEUVCMb', 'dDaX8KCWOR', 'aftXNjLGrr', 'UnfXF08T0Q', 'sXmXshMQ28', 'H9dXAqTuTr', 'DycX9298Uf' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, hI2dV4qa0vWmOJFbgT.cs | High entropy of concatenated method names: 'DTIMTXWWjc', 'Ri5MudsRqV', 'dIoMxq8erg', 'FOJMvCUQJZ', 'vWrMS9T1Oj', 'pBLMo1wqeX', 'E7BMBfR3jk', 'D5XMqDAx9J', 'ITWMIckv0w', 'NTfMJNJfqG' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, iFJ71Rxs79e7aeM5Ur.cs | High entropy of concatenated method names: 'Dispose', 'kHftDM2ZRD', 'IKGhK5qXvU', 'kxaQs6KNTy', 'UbXtgpmvRK', 'bcttzTv3Ix', 'ProcessDialogKey', 'EUNhwAtPNy', 'h6Eht2pKbH', 'J0fhhHEWe2' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, JvB0ZNpGrT387VAaQH.cs | High entropy of concatenated method names: 'TBmvbQt99B', 'vubvRcDZAr', 'z4kv43TSCL', 'K2YvpXe84F', 'xEGv7fEyRD', 'sA8vlpR7Ot', 'f8KvcdVu6W', 'fGovUsakZ0', 'kUPv0g6aYj', 'P0KvXjoOLn' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, vEWe2xgYyqEmZLKkkM.cs | High entropy of concatenated method names: 'xCvXvoEQSp', 'PNpXSgtgNY', 'oT8XoV02gT', 'RqoXBHAoiP', 'EUtX03lyS5', 'yBgXqbbnZ7', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.payment slip______________________pdf.exe.49cc878.0.raw.unpack, bN9Yf3QHRIHfM2ZRDd.cs | High entropy of concatenated method names: 'va707hDpWX', 'EUc0cMNB9k', 'xhB00ufce4', 'oki0iDI9f3', 'OGN0WWUMUe', 'jfk0ayaZXV', 'Dispose', 'L6WUue9er9', 'BmBUxBbwGx', 'TasUvS7CWT' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, yBOQlXeQEM3H2iImIq.cs | High entropy of concatenated method names: 'i61SCOB86F', 'c9ISjMGL1i', 'S0IvnfIKNo', 'iZZv27vxXE', 'ilOvOLyy1a', 'FBFvZayj1j', 'J0IvyVlrp3', 'DkqvmTMpuX', 'AKlvfXMGgt', 'vTDv5yIKtt' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, HHMxicrcplcPFa0Uat.cs | High entropy of concatenated method names: 'yIvcYtQwyV', 'yMicgwlsgC', 'PaFUwKmKt7', 'ybMUtuwS8H', 'B8vcEFgOb3', 'iMBc8B3UJJ', 'Ea0cNfDR9W', 'Tk9cFkdy3k', 'eC8csDRCVx', 'r0DcAh9AOL' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, kYiwP0hu8ikcda3vHI.cs | High entropy of concatenated method names: 'I8x1UY0rQ', 'XBPbmnGVD', 'xArR7Hb11', 'yv8j7MdWh', 'nmTppdGEe', 'caoeTP6aP', 'bHd0CeJdhp8ELgKHYr', 's2wLUxiZ4BO3v8tPUi', 'jTsUrUmTV', 'DPEXh8LLC' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, A5LcZot3BTgauTK284i.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'NybV0bpovd', 'MmUVXDvMhK', 'fQAVitKZmm', 'wkZVVKMUx8', 'VGlVWfRj43', 'TXhVH9cOAU', 'm2MVa7MfeQ' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, KbGYW64TQtPknvF7f1.cs | High entropy of concatenated method names: 'Fk7xFMOFRa', 'a9txsjfBUw', 'sfRxAgnrky', 'b0Kx9wq7AQ', 'Oufxdpa8os', 'nvJxr3xMLD', 'XBxxQOupUc', 'bi8xYNJRbQ', 'L7IxDvAHwS', 'RxExgsm93Q' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, bsqTdhfopvhHVvpu32.cs | High entropy of concatenated method names: 'KNnBPM5L25', 'osOBGrw7f9', 'fwQB1tgdPd', 'cshBbtMBFs', 'nGvBCYOJ0w', 'f06BRsN28e', 'cRgBjkMoIL', 'bb7B4JVmaJ', 'sFSBpcKujk', 'hBoBeJfN0u' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, TfwZiPAo7ejIb1yYkD.cs | High entropy of concatenated method names: 'ToString', 'sASlEDGbcc', 'tAilK8fpeS', 'wb0lnZI9De', 'zCul2MHohw', 'SrrlO9FhLb', 'ieclZUECjT', 'L7Olyhfpus', 'S7GlmS0DtT', 'VqLlfn9Jdc' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, z1kwL7ttjx6EtnXEHld.cs | High entropy of concatenated method names: 'hTkXg4bGO3', 'mwDXzWrnVJ', 'ynkiwL4jpv', 'l8iiteUkCG', 'xAbihE0cwI', 'scIiMxjxQs', 'CcWi32V9Fa', 'WLliTgRlC0', 'GNjiu3ndPf', 'TS4ixnrXEQ' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, GtZCd7FDvBUjg9efA5.cs | High entropy of concatenated method names: 'LXb75aWyKH', 'OCE78Xo57J', 'fZ27FpVeZj', 'ODL7sH2bGZ', 'wh87Kbyr3W', 'UTc7nrRH3o', 'bIh72Z0GgB', 'fBR7O3qmD6', 'Bmf7Z70HgB', 'e2B7y6W59Z' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, WUKNWW3y7PNwVoYhy7.cs | High entropy of concatenated method names: 'mXZtBbGYW6', 'eQttqPknvF', 'PGrtJT387V', 'SaQtkHGBOQ', 'tImt7Iqil6', 'kg2tlAKrhf', 'G2bNW3yHd5wQ28nDHS', 'gFGY7Gavr4aYn5yoUZ', 'pwuttGs3WL', 'hiytMseX06' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, KesChXzAOdWqMcglng.cs | High entropy of concatenated method names: 'QPVXRBubZM', 'LfAX4sMPFe', 'oy6XpLxkhG', 'G2XX6IaGiP', 'u7YXKx1jeS', 'r57X2SugoB', 'SZWXOYHfJc', 'jd3XaQMcRi', 'exPXP1AISR', 'rK6XGluetX' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, zcscPeywLO41sBRm1K.cs | High entropy of concatenated method names: 'xXGBufDF52', 'qgpBvWXx8Y', 'Y3kBo5CVbC', 'USpogc5990', 'iiRozyxaQi', 'FB0Bw6Otld', 'oFMBtXvCId', 'MInBhgH0Af', 'c4sBMm5fp3', 'CKwB3dfrCd' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, M5jMfMvcjF1sChF1AZ.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4IhDtntpW', 'Gbthgpl4GK', 'lUXhzauq1O', 'KF0MwGB4XX', 'nLhMtj1sLE', 'Ae2MhmZdTY', 'cubMMa5NqV', 'cKZAJQovBf2rG5My7hx' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, tl6qg26AKrhfKSSE69.cs | High entropy of concatenated method names: 'zYnoTJrlp2', 'bR7ox2wKu3', 'qkJoSga4PH', 'b5UoBeXyo8', 'eZ9oqiVZAq', 'jc0Sd5fn8x', 'tLrSrOiGci', 'DUBSQkRtmG', 'sfRSYGXwWE', 'MKWSD2Cr8k' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, mE3x5T9Qlh7UxTOYtE.cs | High entropy of concatenated method names: 'Bv4cJPrQjV', 'LWLckFsTNp', 'ToString', 'QgGcu93xX9', 'FcicxrBDkt', 'qI3cvPhsYl', 'PSFcSYID8P', 'zSQcoC00x8', 'HLEcBp7gV9', 'Xb9cqrsUw7' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, PAtPNyDv6E2pKbHO0f.cs | High entropy of concatenated method names: 'fUP06dulS9', 'lRo0KOl7SG', 'E7o0nJRTDQ', 'hZr02wsJvx', 'M9o0OHFtNv', 'amr0ZIoDry', 'TYw0ysSZdh', 'AyC0mDEh5F', 'd0e0fNhqQP', 'RvM05iwiBX' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, UUrS32NDkv1vdk1x5k.cs | High entropy of concatenated method names: 'rkrL4V6UoH', 'CbPLpJEcsn', 'YmML6ajkGI', 'BCeLK0lGTj', 'yagL2ZDYWY', 'eqsLO6Flul', 'A9cLygNW03', 'H4GLmNJeB7', 'aU1L56nJQL', 'B1aLExDEk9' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, PNmVxvtwn2Jl6aGCle5.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'xUmXEUVCMb', 'dDaX8KCWOR', 'aftXNjLGrr', 'UnfXF08T0Q', 'sXmXshMQ28', 'H9dXAqTuTr', 'DycX9298Uf' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, hI2dV4qa0vWmOJFbgT.cs | High entropy of concatenated method names: 'DTIMTXWWjc', 'Ri5MudsRqV', 'dIoMxq8erg', 'FOJMvCUQJZ', 'vWrMS9T1Oj', 'pBLMo1wqeX', 'E7BMBfR3jk', 'D5XMqDAx9J', 'ITWMIckv0w', 'NTfMJNJfqG' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, iFJ71Rxs79e7aeM5Ur.cs | High entropy of concatenated method names: 'Dispose', 'kHftDM2ZRD', 'IKGhK5qXvU', 'kxaQs6KNTy', 'UbXtgpmvRK', 'bcttzTv3Ix', 'ProcessDialogKey', 'EUNhwAtPNy', 'h6Eht2pKbH', 'J0fhhHEWe2' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, JvB0ZNpGrT387VAaQH.cs | High entropy of concatenated method names: 'TBmvbQt99B', 'vubvRcDZAr', 'z4kv43TSCL', 'K2YvpXe84F', 'xEGv7fEyRD', 'sA8vlpR7Ot', 'f8KvcdVu6W', 'fGovUsakZ0', 'kUPv0g6aYj', 'P0KvXjoOLn' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, vEWe2xgYyqEmZLKkkM.cs | High entropy of concatenated method names: 'xCvXvoEQSp', 'PNpXSgtgNY', 'oT8XoV02gT', 'RqoXBHAoiP', 'EUtX03lyS5', 'yBgXqbbnZ7', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.payment slip______________________pdf.exe.b700000.5.raw.unpack, bN9Yf3QHRIHfM2ZRDd.cs | High entropy of concatenated method names: 'va707hDpWX', 'EUc0cMNB9k', 'xhB00ufce4', 'oki0iDI9f3', 'OGN0WWUMUe', 'jfk0ayaZXV', 'Dispose', 'L6WUue9er9', 'BmBUxBbwGx', 'TasUvS7CWT' |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Users\user\Desktop\payment slip______________________pdf.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\payment slip______________________pdf.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Users\user\AppData\Roaming\UNTKRsD.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\UNTKRsD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |