Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 6.2.299371485_14108825808_1736351479899.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 6.2.299371485_14108825808_1736351479899.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 6.2.299371485_14108825808_1736351479899.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.299371485_14108825808_1736351479899.exe.433c220.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.299371485_14108825808_1736351479899.exe.437ec40.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000006.00000002.4617089897.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.2219355172.000000000433C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 299371485_14108825808_1736351479899.exe PID: 4876, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 299371485_14108825808_1736351479899.exe PID: 6240, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, qelLwRPCPsGUs6jdyY.cs | High entropy of concatenated method names: 'C4JlbnANLt', 'NEvl8YuQcg', 'NN6lCuaIGq', 'MBClKTQfSr', 'heTlBYamwi', 'CwvlISDKoB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, ggXPZ5pdN41pIJs1V3.cs | High entropy of concatenated method names: 'ilnCo2TpYw', 'jQKCNctpwn', 'g3fCdhQ4Js', 'ToString', 'uj3C4FpJJS', 'SZ2C58A6MS', 'b5LeipymTSahZpCWtVI', 'a1NBaSy4kxFCjHZl6ot', 'qFDxGAyJuBOXAU3uP6S', 'bQbx4HyXSVlTNcxgB9W' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, KiBPZRUmpULxGIDG71.cs | High entropy of concatenated method names: 'vTOKf63TLf', 'Ck4K6KTSyh', 'mpoKMCphDT', 'QUvKvcuiCl', 'sWqKJLKTUR', 'AVkKEThFF6', 'qKhKO19hPd', 'PliKy3LrZg', 'DbjK2KXapj', 'UptKToYVXa' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, vbF4dwbDYXd1pm0UND.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'ARs7Zueo2T', 'fg37PlI7bQ', 'L3e7zbBF6O', 'tWGFrMcMJh', 'HfDFjU0QJp', 'OWqF7ccZXX', 'yYaFF3xJ4A', 'KQhgDkf0myA5Z1vVEcy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, Ad8t06TsdlZPlGJflu.cs | High entropy of concatenated method names: 'WUa8J9DTew', 'wye8OiWCKY', 'NGlbSsUNHx', 'gWlbuiODZG', 'CyHbXdruHc', 'Gfkbp0H53H', 'NTYbW5uH0F', 'zAhbmigu3E', 'JTvbUr7yE6', 'f39biBHtB9' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, nJfbfko7qhviuIACOm.cs | High entropy of concatenated method names: 'ToString', 'nUvQ0x5mpP', 'yo1QcUWHr2', 'hI2QSgYY72', 'XCdQu7q9R5', 'crEQXSZicJ', 'A2eQpoBqck', 'GK2QW1LDF5', 'dHBQmj1QsF', 'veDQUTGIxR' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, Ru23Huyb8mQLjC7BwH.cs | High entropy of concatenated method names: 'qKNqtcoNRU', 'tMRqh655Hk', 'cydqohwEm1', 'lRmqNULURh', 'YdiqdpFKUc', 'YtEq4FoWAb', 'HCMq52QiOf', 'uP5qatB1SB', 'VRjqZoTOF2', 'EtZqPV98Aq' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, zuDh9WIx1svT8dxSDC.cs | High entropy of concatenated method names: 'nNWF1G7MHU', 'yIKFGqwVsM', 'gJUFqwRMVG', 'SoqFbPyRkr', 'dIhF8RGr9t', 'mmlFCbEW2s', 'kfSFK0ejw5', 'xjaFI39hgS', 'iPqFwPHaio', 'nLsFns5SaE' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, UQ2KwGjrcRdMFjeybgG.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qqCl0TGnC8', 'QRblDiKoFe', 'YrClL35cag', 'o4xltb0hSF', 'uJ1lhHiIN9', 'JcyloCa4T2', 'lK8lNLhq2E' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, NvlJnjtLs8bdgXBD99.cs | High entropy of concatenated method names: 'CUDeimJgTS', 'qh4eD0ZMSv', 'uAoet9Dgbd', 'KUMehq5Pgl', 'b1GecRRf2P', 'cIAeSuTxAi', 'GdEeuXwLNU', 'qHBeXjJMf9', 'cKcepgQvyC', 'VeDeWRNpAd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, vFBqrTW7LF9gFQ3SS9.cs | High entropy of concatenated method names: 'YusKGfnxTw', 'mFNKbjNWGJ', 'v0kKCBJvHc', 'kTBCPS9JUJ', 'naUCziBAwT', 'AhEKr6FPyy', 'UJ9KjNWpGN', 'uaUK7eDKgu', 'jZxKFcfu0H', 'oiKK9Fo6dd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, w4aIYZZAxAL81mU4Pf.cs | High entropy of concatenated method names: 'tbsBYQAIjb', 'Qj8BcmckrZ', 'ci1BSALIuO', 'vq8BuU9VUD', 'iQWBXj6b9E', 'wigBpJdmud', 'xDwBWsIw0b', 'gveBmn9kue', 'F76BU0DIOI', 'GF1Bi71EUZ' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, I7L8C6N1ebf5t9UBNB.cs | High entropy of concatenated method names: 'GhwAnyibkG', 'qKtAsiCy08', 'ToString', 'Q4JAGOYMHa', 'ydLAqEDiSj', 'V73Ab35N3p', 'tiYA8kcdEJ', 'KWeACNh0Vu', 'NZpAK75mWm', 'i0OAIG4CMK' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, qFpaCg4OeA9gyeZYvB.cs | High entropy of concatenated method names: 'cRMAa0XpJN', 'FimAPvP2jr', 'FEnxroRaLi', 'D1YxjmDc24', 'D1IA0jrwGL', 'kggADFGiWg', 'PHEALmoOf0', 'HYFAtRYgdn', 'NOCAhQxFUg', 'NT7Aok0MCh' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, XEbj01c6HjltfqTAYO.cs | High entropy of concatenated method names: 'R6HG07yaTT7p1wrHxiQ', 'jWnbt4yFKwV4f4O8La3', 'Lb4CxmI65B', 'dS1CBVcFBL', 'fCYClqspom', 'k91DwNyYu1JU3W8CJkA', 'enG5bAyRxepn5Q9TkCu' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, a6ErcFYOWqRCf0yytN.cs | High entropy of concatenated method names: 'qd2C1YF2aN', 'CHsCqUSZab', 'YBpC8bDBWf', 'IT6CKBNg4O', 'l0nCIjIysJ', 'WOk8dqRp0M', 'fwx84ULr0r', 'Ryy85rxqRc', 'X8I8aXN9dA', 'eNA8ZJh3yl' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, VTwGxuj9BXOw3aUhmTr.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'kdVVB6UQ1d', 'xNmVlKFttY', 'f95VgPgmlT', 'yCXVV9C06G', 'f6jV3nqVgZ', 'jKMVHAUR3I', 'FvUVR1pUNb' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, Xps7qRzTcm6j2O5EgP.cs | High entropy of concatenated method names: 'fbFlEUaWEi', 'm87lydFlV7', 'dPbl2cJ0k6', 'vMolY90eWD', 'b58lcEeXVy', 'z0FluM8CNn', 'bE3lXil51Y', 'borlRHJdHa', 'gySlf1nh3m', 'r1Vl6mHovj' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, GmQF5c96kjSSXmTedq.cs | High entropy of concatenated method names: 'v0tjKu23Hu', 'g8mjIQLjC7', 'NkhjnIBVLA', 'i5ejsCvd8t', 'fJfjelur6E', 'acFjQOWqRC', 'wjMxeVddQy3O8n4b3E', 'i9JQ60n6NPoaj2Jir7', 'O6bjjELi8v', 'K1OjFPPdsk' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, nrtLcTjjDPGqy3J5J8r.cs | High entropy of concatenated method names: 'zSclPJQaLc', 'LnKlznPo8e', 'y5pgrn35kf', 'stNgjlSHee', 'W59g79iVOf', 'TjVgFqUOmi', 'qqDg9UkcZ1', 'eU9g1kJFbd', 'hFrgG8xD90', 'fmwgqL9dx5' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, VushkvqOit4FjNAy9I.cs | High entropy of concatenated method names: 'Dispose', 'EuIjZeQ4LD', 'FyC7codZQ0', 'hFlOXJLFwU', 'VFyjPGK9yc', 'pqVjzNt61m', 'ProcessDialogKey', 'rMH7r4aIYZ', 'qxA7jL81mU', 'VPf77AelLw' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, Xhifmp5Im2uIeQ4LD5.cs | High entropy of concatenated method names: 'VLhBeDH9r4', 'PpyBAd6Ll1', 'LFEBBnyoGc', 'EECBg9iGtG', 'LxtB3R6WMg', 'REgBRqM5SU', 'Dispose', 'UwOxGpbd10', 'rg3xqEOBwh', 'BS8xbboLWy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, ruDEOU2khIBVLAC5eC.cs | High entropy of concatenated method names: 'KZ8bvO40Wr', 'sQEbEXJDhl', 'ffqbyfoUww', 'eKDb2Q4MtS', 'O2FbebY4uW', 'wxdbQHmMpS', 'zOBbAUQdbj', 'BbIbx5nb5X', 'lbMbBl5DUD', 'ot8bllxglN' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, cbbtMY7GD7d1iUYhAX.cs | High entropy of concatenated method names: 'q5GMGslJM', 'EQyvUl5iu', 'CoDE5XOKS', 'b1COhJQJH', 'naI2m2o8C', 'A1hTPLsN0', 'NETVDVLfcWVTSqcl8g', 'nfmL13G8xZw2qfad3n', 'V6TxipDOr', 'oR1lhV4Dv' |
Source: 0.2.299371485_14108825808_1736351479899.exe.9b20000.6.raw.unpack, UIgDiRLwSiBdvbIDpp.cs | High entropy of concatenated method names: 'lrPky6NOEY', 'nYvk27DFfA', 'fxnkY9KjQu', 'eYYkcs2k12', 'fEAkuyg4Ey', 'exnkXUy3PT', 'J97kWEtmIx', 'nWtkmoj9mT', 't9mkic3TWQ', 'FVdk0RySk6' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, qelLwRPCPsGUs6jdyY.cs | High entropy of concatenated method names: 'C4JlbnANLt', 'NEvl8YuQcg', 'NN6lCuaIGq', 'MBClKTQfSr', 'heTlBYamwi', 'CwvlISDKoB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, ggXPZ5pdN41pIJs1V3.cs | High entropy of concatenated method names: 'ilnCo2TpYw', 'jQKCNctpwn', 'g3fCdhQ4Js', 'ToString', 'uj3C4FpJJS', 'SZ2C58A6MS', 'b5LeipymTSahZpCWtVI', 'a1NBaSy4kxFCjHZl6ot', 'qFDxGAyJuBOXAU3uP6S', 'bQbx4HyXSVlTNcxgB9W' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, KiBPZRUmpULxGIDG71.cs | High entropy of concatenated method names: 'vTOKf63TLf', 'Ck4K6KTSyh', 'mpoKMCphDT', 'QUvKvcuiCl', 'sWqKJLKTUR', 'AVkKEThFF6', 'qKhKO19hPd', 'PliKy3LrZg', 'DbjK2KXapj', 'UptKToYVXa' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, vbF4dwbDYXd1pm0UND.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'ARs7Zueo2T', 'fg37PlI7bQ', 'L3e7zbBF6O', 'tWGFrMcMJh', 'HfDFjU0QJp', 'OWqF7ccZXX', 'yYaFF3xJ4A', 'KQhgDkf0myA5Z1vVEcy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, Ad8t06TsdlZPlGJflu.cs | High entropy of concatenated method names: 'WUa8J9DTew', 'wye8OiWCKY', 'NGlbSsUNHx', 'gWlbuiODZG', 'CyHbXdruHc', 'Gfkbp0H53H', 'NTYbW5uH0F', 'zAhbmigu3E', 'JTvbUr7yE6', 'f39biBHtB9' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, nJfbfko7qhviuIACOm.cs | High entropy of concatenated method names: 'ToString', 'nUvQ0x5mpP', 'yo1QcUWHr2', 'hI2QSgYY72', 'XCdQu7q9R5', 'crEQXSZicJ', 'A2eQpoBqck', 'GK2QW1LDF5', 'dHBQmj1QsF', 'veDQUTGIxR' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, Ru23Huyb8mQLjC7BwH.cs | High entropy of concatenated method names: 'qKNqtcoNRU', 'tMRqh655Hk', 'cydqohwEm1', 'lRmqNULURh', 'YdiqdpFKUc', 'YtEq4FoWAb', 'HCMq52QiOf', 'uP5qatB1SB', 'VRjqZoTOF2', 'EtZqPV98Aq' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, zuDh9WIx1svT8dxSDC.cs | High entropy of concatenated method names: 'nNWF1G7MHU', 'yIKFGqwVsM', 'gJUFqwRMVG', 'SoqFbPyRkr', 'dIhF8RGr9t', 'mmlFCbEW2s', 'kfSFK0ejw5', 'xjaFI39hgS', 'iPqFwPHaio', 'nLsFns5SaE' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, UQ2KwGjrcRdMFjeybgG.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qqCl0TGnC8', 'QRblDiKoFe', 'YrClL35cag', 'o4xltb0hSF', 'uJ1lhHiIN9', 'JcyloCa4T2', 'lK8lNLhq2E' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, NvlJnjtLs8bdgXBD99.cs | High entropy of concatenated method names: 'CUDeimJgTS', 'qh4eD0ZMSv', 'uAoet9Dgbd', 'KUMehq5Pgl', 'b1GecRRf2P', 'cIAeSuTxAi', 'GdEeuXwLNU', 'qHBeXjJMf9', 'cKcepgQvyC', 'VeDeWRNpAd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, vFBqrTW7LF9gFQ3SS9.cs | High entropy of concatenated method names: 'YusKGfnxTw', 'mFNKbjNWGJ', 'v0kKCBJvHc', 'kTBCPS9JUJ', 'naUCziBAwT', 'AhEKr6FPyy', 'UJ9KjNWpGN', 'uaUK7eDKgu', 'jZxKFcfu0H', 'oiKK9Fo6dd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, w4aIYZZAxAL81mU4Pf.cs | High entropy of concatenated method names: 'tbsBYQAIjb', 'Qj8BcmckrZ', 'ci1BSALIuO', 'vq8BuU9VUD', 'iQWBXj6b9E', 'wigBpJdmud', 'xDwBWsIw0b', 'gveBmn9kue', 'F76BU0DIOI', 'GF1Bi71EUZ' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, I7L8C6N1ebf5t9UBNB.cs | High entropy of concatenated method names: 'GhwAnyibkG', 'qKtAsiCy08', 'ToString', 'Q4JAGOYMHa', 'ydLAqEDiSj', 'V73Ab35N3p', 'tiYA8kcdEJ', 'KWeACNh0Vu', 'NZpAK75mWm', 'i0OAIG4CMK' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, qFpaCg4OeA9gyeZYvB.cs | High entropy of concatenated method names: 'cRMAa0XpJN', 'FimAPvP2jr', 'FEnxroRaLi', 'D1YxjmDc24', 'D1IA0jrwGL', 'kggADFGiWg', 'PHEALmoOf0', 'HYFAtRYgdn', 'NOCAhQxFUg', 'NT7Aok0MCh' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, XEbj01c6HjltfqTAYO.cs | High entropy of concatenated method names: 'R6HG07yaTT7p1wrHxiQ', 'jWnbt4yFKwV4f4O8La3', 'Lb4CxmI65B', 'dS1CBVcFBL', 'fCYClqspom', 'k91DwNyYu1JU3W8CJkA', 'enG5bAyRxepn5Q9TkCu' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, a6ErcFYOWqRCf0yytN.cs | High entropy of concatenated method names: 'qd2C1YF2aN', 'CHsCqUSZab', 'YBpC8bDBWf', 'IT6CKBNg4O', 'l0nCIjIysJ', 'WOk8dqRp0M', 'fwx84ULr0r', 'Ryy85rxqRc', 'X8I8aXN9dA', 'eNA8ZJh3yl' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, VTwGxuj9BXOw3aUhmTr.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'kdVVB6UQ1d', 'xNmVlKFttY', 'f95VgPgmlT', 'yCXVV9C06G', 'f6jV3nqVgZ', 'jKMVHAUR3I', 'FvUVR1pUNb' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, Xps7qRzTcm6j2O5EgP.cs | High entropy of concatenated method names: 'fbFlEUaWEi', 'm87lydFlV7', 'dPbl2cJ0k6', 'vMolY90eWD', 'b58lcEeXVy', 'z0FluM8CNn', 'bE3lXil51Y', 'borlRHJdHa', 'gySlf1nh3m', 'r1Vl6mHovj' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, GmQF5c96kjSSXmTedq.cs | High entropy of concatenated method names: 'v0tjKu23Hu', 'g8mjIQLjC7', 'NkhjnIBVLA', 'i5ejsCvd8t', 'fJfjelur6E', 'acFjQOWqRC', 'wjMxeVddQy3O8n4b3E', 'i9JQ60n6NPoaj2Jir7', 'O6bjjELi8v', 'K1OjFPPdsk' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, nrtLcTjjDPGqy3J5J8r.cs | High entropy of concatenated method names: 'zSclPJQaLc', 'LnKlznPo8e', 'y5pgrn35kf', 'stNgjlSHee', 'W59g79iVOf', 'TjVgFqUOmi', 'qqDg9UkcZ1', 'eU9g1kJFbd', 'hFrgG8xD90', 'fmwgqL9dx5' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, VushkvqOit4FjNAy9I.cs | High entropy of concatenated method names: 'Dispose', 'EuIjZeQ4LD', 'FyC7codZQ0', 'hFlOXJLFwU', 'VFyjPGK9yc', 'pqVjzNt61m', 'ProcessDialogKey', 'rMH7r4aIYZ', 'qxA7jL81mU', 'VPf77AelLw' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, Xhifmp5Im2uIeQ4LD5.cs | High entropy of concatenated method names: 'VLhBeDH9r4', 'PpyBAd6Ll1', 'LFEBBnyoGc', 'EECBg9iGtG', 'LxtB3R6WMg', 'REgBRqM5SU', 'Dispose', 'UwOxGpbd10', 'rg3xqEOBwh', 'BS8xbboLWy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, ruDEOU2khIBVLAC5eC.cs | High entropy of concatenated method names: 'KZ8bvO40Wr', 'sQEbEXJDhl', 'ffqbyfoUww', 'eKDb2Q4MtS', 'O2FbebY4uW', 'wxdbQHmMpS', 'zOBbAUQdbj', 'BbIbx5nb5X', 'lbMbBl5DUD', 'ot8bllxglN' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, cbbtMY7GD7d1iUYhAX.cs | High entropy of concatenated method names: 'q5GMGslJM', 'EQyvUl5iu', 'CoDE5XOKS', 'b1COhJQJH', 'naI2m2o8C', 'A1hTPLsN0', 'NETVDVLfcWVTSqcl8g', 'nfmL13G8xZw2qfad3n', 'V6TxipDOr', 'oR1lhV4Dv' |
Source: 0.2.299371485_14108825808_1736351479899.exe.41f3088.1.raw.unpack, UIgDiRLwSiBdvbIDpp.cs | High entropy of concatenated method names: 'lrPky6NOEY', 'nYvk27DFfA', 'fxnkY9KjQu', 'eYYkcs2k12', 'fEAkuyg4Ey', 'exnkXUy3PT', 'J97kWEtmIx', 'nWtkmoj9mT', 't9mkic3TWQ', 'FVdk0RySk6' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, qelLwRPCPsGUs6jdyY.cs | High entropy of concatenated method names: 'C4JlbnANLt', 'NEvl8YuQcg', 'NN6lCuaIGq', 'MBClKTQfSr', 'heTlBYamwi', 'CwvlISDKoB', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, ggXPZ5pdN41pIJs1V3.cs | High entropy of concatenated method names: 'ilnCo2TpYw', 'jQKCNctpwn', 'g3fCdhQ4Js', 'ToString', 'uj3C4FpJJS', 'SZ2C58A6MS', 'b5LeipymTSahZpCWtVI', 'a1NBaSy4kxFCjHZl6ot', 'qFDxGAyJuBOXAU3uP6S', 'bQbx4HyXSVlTNcxgB9W' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, KiBPZRUmpULxGIDG71.cs | High entropy of concatenated method names: 'vTOKf63TLf', 'Ck4K6KTSyh', 'mpoKMCphDT', 'QUvKvcuiCl', 'sWqKJLKTUR', 'AVkKEThFF6', 'qKhKO19hPd', 'PliKy3LrZg', 'DbjK2KXapj', 'UptKToYVXa' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, vbF4dwbDYXd1pm0UND.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'ARs7Zueo2T', 'fg37PlI7bQ', 'L3e7zbBF6O', 'tWGFrMcMJh', 'HfDFjU0QJp', 'OWqF7ccZXX', 'yYaFF3xJ4A', 'KQhgDkf0myA5Z1vVEcy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, Ad8t06TsdlZPlGJflu.cs | High entropy of concatenated method names: 'WUa8J9DTew', 'wye8OiWCKY', 'NGlbSsUNHx', 'gWlbuiODZG', 'CyHbXdruHc', 'Gfkbp0H53H', 'NTYbW5uH0F', 'zAhbmigu3E', 'JTvbUr7yE6', 'f39biBHtB9' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, nJfbfko7qhviuIACOm.cs | High entropy of concatenated method names: 'ToString', 'nUvQ0x5mpP', 'yo1QcUWHr2', 'hI2QSgYY72', 'XCdQu7q9R5', 'crEQXSZicJ', 'A2eQpoBqck', 'GK2QW1LDF5', 'dHBQmj1QsF', 'veDQUTGIxR' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, Ru23Huyb8mQLjC7BwH.cs | High entropy of concatenated method names: 'qKNqtcoNRU', 'tMRqh655Hk', 'cydqohwEm1', 'lRmqNULURh', 'YdiqdpFKUc', 'YtEq4FoWAb', 'HCMq52QiOf', 'uP5qatB1SB', 'VRjqZoTOF2', 'EtZqPV98Aq' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, zuDh9WIx1svT8dxSDC.cs | High entropy of concatenated method names: 'nNWF1G7MHU', 'yIKFGqwVsM', 'gJUFqwRMVG', 'SoqFbPyRkr', 'dIhF8RGr9t', 'mmlFCbEW2s', 'kfSFK0ejw5', 'xjaFI39hgS', 'iPqFwPHaio', 'nLsFns5SaE' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, UQ2KwGjrcRdMFjeybgG.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qqCl0TGnC8', 'QRblDiKoFe', 'YrClL35cag', 'o4xltb0hSF', 'uJ1lhHiIN9', 'JcyloCa4T2', 'lK8lNLhq2E' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, NvlJnjtLs8bdgXBD99.cs | High entropy of concatenated method names: 'CUDeimJgTS', 'qh4eD0ZMSv', 'uAoet9Dgbd', 'KUMehq5Pgl', 'b1GecRRf2P', 'cIAeSuTxAi', 'GdEeuXwLNU', 'qHBeXjJMf9', 'cKcepgQvyC', 'VeDeWRNpAd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, vFBqrTW7LF9gFQ3SS9.cs | High entropy of concatenated method names: 'YusKGfnxTw', 'mFNKbjNWGJ', 'v0kKCBJvHc', 'kTBCPS9JUJ', 'naUCziBAwT', 'AhEKr6FPyy', 'UJ9KjNWpGN', 'uaUK7eDKgu', 'jZxKFcfu0H', 'oiKK9Fo6dd' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, w4aIYZZAxAL81mU4Pf.cs | High entropy of concatenated method names: 'tbsBYQAIjb', 'Qj8BcmckrZ', 'ci1BSALIuO', 'vq8BuU9VUD', 'iQWBXj6b9E', 'wigBpJdmud', 'xDwBWsIw0b', 'gveBmn9kue', 'F76BU0DIOI', 'GF1Bi71EUZ' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, I7L8C6N1ebf5t9UBNB.cs | High entropy of concatenated method names: 'GhwAnyibkG', 'qKtAsiCy08', 'ToString', 'Q4JAGOYMHa', 'ydLAqEDiSj', 'V73Ab35N3p', 'tiYA8kcdEJ', 'KWeACNh0Vu', 'NZpAK75mWm', 'i0OAIG4CMK' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, qFpaCg4OeA9gyeZYvB.cs | High entropy of concatenated method names: 'cRMAa0XpJN', 'FimAPvP2jr', 'FEnxroRaLi', 'D1YxjmDc24', 'D1IA0jrwGL', 'kggADFGiWg', 'PHEALmoOf0', 'HYFAtRYgdn', 'NOCAhQxFUg', 'NT7Aok0MCh' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, XEbj01c6HjltfqTAYO.cs | High entropy of concatenated method names: 'R6HG07yaTT7p1wrHxiQ', 'jWnbt4yFKwV4f4O8La3', 'Lb4CxmI65B', 'dS1CBVcFBL', 'fCYClqspom', 'k91DwNyYu1JU3W8CJkA', 'enG5bAyRxepn5Q9TkCu' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, a6ErcFYOWqRCf0yytN.cs | High entropy of concatenated method names: 'qd2C1YF2aN', 'CHsCqUSZab', 'YBpC8bDBWf', 'IT6CKBNg4O', 'l0nCIjIysJ', 'WOk8dqRp0M', 'fwx84ULr0r', 'Ryy85rxqRc', 'X8I8aXN9dA', 'eNA8ZJh3yl' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, VTwGxuj9BXOw3aUhmTr.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'kdVVB6UQ1d', 'xNmVlKFttY', 'f95VgPgmlT', 'yCXVV9C06G', 'f6jV3nqVgZ', 'jKMVHAUR3I', 'FvUVR1pUNb' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, Xps7qRzTcm6j2O5EgP.cs | High entropy of concatenated method names: 'fbFlEUaWEi', 'm87lydFlV7', 'dPbl2cJ0k6', 'vMolY90eWD', 'b58lcEeXVy', 'z0FluM8CNn', 'bE3lXil51Y', 'borlRHJdHa', 'gySlf1nh3m', 'r1Vl6mHovj' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, GmQF5c96kjSSXmTedq.cs | High entropy of concatenated method names: 'v0tjKu23Hu', 'g8mjIQLjC7', 'NkhjnIBVLA', 'i5ejsCvd8t', 'fJfjelur6E', 'acFjQOWqRC', 'wjMxeVddQy3O8n4b3E', 'i9JQ60n6NPoaj2Jir7', 'O6bjjELi8v', 'K1OjFPPdsk' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, nrtLcTjjDPGqy3J5J8r.cs | High entropy of concatenated method names: 'zSclPJQaLc', 'LnKlznPo8e', 'y5pgrn35kf', 'stNgjlSHee', 'W59g79iVOf', 'TjVgFqUOmi', 'qqDg9UkcZ1', 'eU9g1kJFbd', 'hFrgG8xD90', 'fmwgqL9dx5' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, VushkvqOit4FjNAy9I.cs | High entropy of concatenated method names: 'Dispose', 'EuIjZeQ4LD', 'FyC7codZQ0', 'hFlOXJLFwU', 'VFyjPGK9yc', 'pqVjzNt61m', 'ProcessDialogKey', 'rMH7r4aIYZ', 'qxA7jL81mU', 'VPf77AelLw' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, Xhifmp5Im2uIeQ4LD5.cs | High entropy of concatenated method names: 'VLhBeDH9r4', 'PpyBAd6Ll1', 'LFEBBnyoGc', 'EECBg9iGtG', 'LxtB3R6WMg', 'REgBRqM5SU', 'Dispose', 'UwOxGpbd10', 'rg3xqEOBwh', 'BS8xbboLWy' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, ruDEOU2khIBVLAC5eC.cs | High entropy of concatenated method names: 'KZ8bvO40Wr', 'sQEbEXJDhl', 'ffqbyfoUww', 'eKDb2Q4MtS', 'O2FbebY4uW', 'wxdbQHmMpS', 'zOBbAUQdbj', 'BbIbx5nb5X', 'lbMbBl5DUD', 'ot8bllxglN' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, cbbtMY7GD7d1iUYhAX.cs | High entropy of concatenated method names: 'q5GMGslJM', 'EQyvUl5iu', 'CoDE5XOKS', 'b1COhJQJH', 'naI2m2o8C', 'A1hTPLsN0', 'NETVDVLfcWVTSqcl8g', 'nfmL13G8xZw2qfad3n', 'V6TxipDOr', 'oR1lhV4Dv' |
Source: 0.2.299371485_14108825808_1736351479899.exe.4279ea8.3.raw.unpack, UIgDiRLwSiBdvbIDpp.cs | High entropy of concatenated method names: 'lrPky6NOEY', 'nYvk27DFfA', 'fxnkY9KjQu', 'eYYkcs2k12', 'fEAkuyg4Ey', 'exnkXUy3PT', 'J97kWEtmIx', 'nWtkmoj9mT', 't9mkic3TWQ', 'FVdk0RySk6' |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599762 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597905 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597577 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597358 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595827 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594952 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594625 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6944 | Thread sleep time: -10145709240540247s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -24903104499507879s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 5660 | Thread sleep count: 2320 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 5660 | Thread sleep count: 7539 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599762s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -599000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598124s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -598015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597905s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597577s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597468s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597358s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -597031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596922s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596265s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -596047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595827s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595390s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -595062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -594952s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -594843s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -594734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe TID: 1908 | Thread sleep time: -594625s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599762 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597905 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597577 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597358 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595827 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594952 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Thread delayed: delay time: 594625 | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\299371485_14108825808_1736351479899.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |