Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4483172378.0000000000434000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4483176808.0000000000433000.00000040.00000400.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4483176808.0000000000433000.00000040.00000400.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4483172378.0000000000434000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: powershell.exe, 00000003.00000002.2060845922.0000000005729000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000003.00000002.2046510253.0000000004815000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000003.00000002.2046510253.0000000004815000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2035924759.0000000002B11000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.2046510253.00000000046C1000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2075038061.00000000030C1000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000003.00000002.2046510253.0000000004815000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, WheTgQY.exe.0.dr | String found in binary or memory: http://tempuri.org/DataTableUsers.xsd |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4483176808.0000000000433000.00000040.00000400.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002A51000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000027F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://varders.kozow.com:8081 |
Source: powershell.exe, 00000003.00000002.2046510253.0000000004815000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4500335062.0000000003813000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: powershell.exe, 00000003.00000002.2046510253.00000000046C1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore6lBeq |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4483176808.0000000000435000.00000040.00000400.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:783875%0D%0ADate%20a |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4500335062.0000000003813000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4500335062.0000000003813000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4500335062.0000000003813000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: WheTgQY.exe, 00000010.00000002.4491033663.00000000029B3000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000029A4000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000029E4000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002C0F000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000029AE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enlBeq |
Source: WheTgQY.exe, 00000010.00000002.4491033663.00000000029A4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enx |
Source: powershell.exe, 00000003.00000002.2060845922.0000000005729000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000003.00000002.2060845922.0000000005729000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000003.00000002.2060845922.0000000005729000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: powershell.exe, 00000003.00000002.2046510253.0000000004815000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000003.00000002.2060845922.0000000005729000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B10000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002AA0000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.000000000283F000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002AA0000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4483172378.0000000000434000.00000040.00000400.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.000000000283F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: WheTgQY.exe, 00000010.00000002.4491033663.00000000028AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189 |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B38000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002B10000.00000004.00000800.00020000.00000000.sdmp, T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002ACA000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028D7000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.000000000286A000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4500335062.0000000003813000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4500304672.0000000003A72000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: WheTgQY.exe, 00000010.00000002.4491033663.00000000029E4000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000028FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/ |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4491137274.0000000002C40000.00000004.00000800.00020000.00000000.sdmp, WheTgQY.exe, 00000010.00000002.4491033663.00000000029DF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/lBeq |
Source: WheTgQY.exe, 00000010.00000002.4491033663.00000000029D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/x |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_010CE044 | 0_2_010CE044 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_05BB8588 | 0_2_05BB8588 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_05BB0006 | 0_2_05BB0006 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_05BB0040 | 0_2_05BB0040 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_05BB8AA7 | 0_2_05BB8AA7 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_05BBB902 | 0_2_05BBB902 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07565170 | 0_2_07565170 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07560A20 | 0_2_07560A20 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07565451 | 0_2_07565451 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_0756C458 | 0_2_0756C458 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07565460 | 0_2_07565460 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07565160 | 0_2_07565160 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_075641DF | 0_2_075641DF |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_075641F0 | 0_2_075641F0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_075641B9 | 0_2_075641B9 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_0756C020 | 0_2_0756C020 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_0756E0D0 | 0_2_0756E0D0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_0756DC98 | 0_2_0756DC98 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07562BF8 | 0_2_07562BF8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_07560A10 | 0_2_07560A10 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_0756D860 | 0_2_0756D860 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_077C4E30 | 0_2_077C4E30 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_08F30A80 | 0_2_08F30A80 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_08F3F0A9 | 0_2_08F3F0A9 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 0_2_08F30A70 | 0_2_08F30A70 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_0308E044 | 9_2_0308E044 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C18588 | 9_2_05C18588 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C10040 | 9_2_05C10040 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C10007 | 9_2_05C10007 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C1B8F8 | 9_2_05C1B8F8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C5460 | 9_2_077C5460 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C5170 | 9_2_077C5170 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C0A20 | 9_2_077C0A20 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077CC458 | 9_2_077CC458 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C5451 | 9_2_077C5451 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C5160 | 9_2_077C5160 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C41F0 | 9_2_077C41F0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C41EF | 9_2_077C41EF |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C41B9 | 9_2_077C41B9 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077CC020 | 9_2_077CC020 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077CE0D0 | 9_2_077CE0D0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077CDC98 | 9_2_077CDC98 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C2BF8 | 9_2_077C2BF8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077C0A10 | 9_2_077C0A10 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_077CD860 | 9_2_077CD860 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_09070A80 | 9_2_09070A80 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_0907F0A9 | 9_2_0907F0A9 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_09070A70 | 9_2_09070A70 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C18ADA | 9_2_05C18ADA |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 9_2_05C18AE8 | 9_2_05C18AE8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111C147 | 10_2_0111C147 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_01115362 | 10_2_01115362 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111D278 | 10_2_0111D278 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111C468 | 10_2_0111C468 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111C738 | 10_2_0111C738 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111E988 | 10_2_0111E988 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_011169A0 | 10_2_011169A0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111CA08 | 10_2_0111CA08 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_01119DE0 | 10_2_01119DE0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111CCD8 | 10_2_0111CCD8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111CFA9 | 10_2_0111CFA9 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_01116FC8 | 10_2_01116FC8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_01113E09 | 10_2_01113E09 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111F630 | 10_2_0111F630 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111E97A | 10_2_0111E97A |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_011139F0 | 10_2_011139F0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_011129EC | 10_2_011129EC |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_0111FA88 | 10_2_0111FA88 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_01113AA1 | 10_2_01113AA1 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D9548 | 10_2_055D9548 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D9C18 | 10_2_055D9C18 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DE6B0 | 10_2_055DE6B0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D5028 | 10_2_055D5028 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD550 | 10_2_055DD550 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD540 | 10_2_055DD540 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DDDFF | 10_2_055DDDFF |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DDDF1 | 10_2_055DDDF1 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DFC68 | 10_2_055DFC68 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DCCA0 | 10_2_055DCCA0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DEF60 | 10_2_055DEF60 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D178F | 10_2_055D178F |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D17A0 | 10_2_055D17A0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D1E70 | 10_2_055D1E70 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DDE00 | 10_2_055DDE00 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D1E80 | 10_2_055D1E80 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DE6AF | 10_2_055DE6AF |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DE6A0 | 10_2_055DE6A0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D2968 | 10_2_055D2968 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD999 | 10_2_055DD999 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD9A8 | 10_2_055DD9A8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD9A7 | 10_2_055DD9A7 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D0040 | 10_2_055D0040 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D5018 | 10_2_055D5018 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DF810 | 10_2_055DF810 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D0006 | 10_2_055D0006 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DF801 | 10_2_055DF801 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D003F | 10_2_055D003F |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DD0F8 | 10_2_055DD0F8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DEB08 | 10_2_055DEB08 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D0B30 | 10_2_055D0B30 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D9328 | 10_2_055D9328 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D0B20 | 10_2_055D0B20 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D8B90 | 10_2_055D8B90 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DF3B8 | 10_2_055DF3B8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DF3A8 | 10_2_055DF3A8 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055D8BA0 | 10_2_055D8BA0 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DE258 | 10_2_055DE258 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DE249 | 10_2_055DE249 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Code function: 10_2_055DEAF8 | 10_2_055DEAF8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAC147 | 16_2_00DAC147 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAD278 | 16_2_00DAD278 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA5362 | 16_2_00DA5362 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAC468 | 16_2_00DAC468 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAC738 | 16_2_00DAC738 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAE988 | 16_2_00DAE988 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA69A0 | 16_2_00DA69A0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DACA08 | 16_2_00DACA08 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DACCD8 | 16_2_00DACCD8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA9DE0 | 16_2_00DA9DE0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA6FC8 | 16_2_00DA6FC8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DACFA9 | 16_2_00DACFA9 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAF631 | 16_2_00DAF631 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA29EC | 16_2_00DA29EC |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA39ED | 16_2_00DA39ED |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAE97A | 16_2_00DAE97A |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DAFA88 | 16_2_00DAFA88 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_00DA3E09 | 16_2_00DA3E09 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651DE00 | 16_2_0651DE00 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06511E80 | 16_2_06511E80 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_065117A0 | 16_2_065117A0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06519C18 | 16_2_06519C18 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06519548 | 16_2_06519548 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06510B30 | 16_2_06510B30 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06515028 | 16_2_06515028 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06512968 | 16_2_06512968 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06511E70 | 16_2_06511E70 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651E6B0 | 16_2_0651E6B0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651E6AF | 16_2_0651E6AF |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651EF51 | 16_2_0651EF51 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651EF60 | 16_2_0651EF60 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651178F | 16_2_0651178F |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651FC5E | 16_2_0651FC5E |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651FC68 | 16_2_0651FC68 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651CC8F | 16_2_0651CC8F |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651CCA0 | 16_2_0651CCA0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651D550 | 16_2_0651D550 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651D540 | 16_2_0651D540 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651DDFF | 16_2_0651DDFF |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651E258 | 16_2_0651E258 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651E24B | 16_2_0651E24B |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651EAF8 | 16_2_0651EAF8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651EB08 | 16_2_0651EB08 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06510B20 | 16_2_06510B20 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06519328 | 16_2_06519328 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06518B90 | 16_2_06518B90 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651F3B8 | 16_2_0651F3B8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06518BA0 | 16_2_06518BA0 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651F3A8 | 16_2_0651F3A8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06510040 | 16_2_06510040 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651F810 | 16_2_0651F810 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06515018 | 16_2_06515018 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651F803 | 16_2_0651F803 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_06510006 | 16_2_06510006 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651D0F8 | 16_2_0651D0F8 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651295A | 16_2_0651295A |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651D999 | 16_2_0651D999 |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Code function: 16_2_0651D9A8 | 16_2_0651D9A8 |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 9.2.WheTgQY.exe.411c3d0.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 9.2.WheTgQY.exe.411c3d0.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 9.2.WheTgQY.exe.411c3d0.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 9.2.WheTgQY.exe.415f3f0.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 9.2.WheTgQY.exe.415f3f0.2.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 9.2.WheTgQY.exe.415f3f0.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.471ffb0.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 9.2.WheTgQY.exe.415f3f0.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 9.2.WheTgQY.exe.415f3f0.2.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 9.2.WheTgQY.exe.415f3f0.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 9.2.WheTgQY.exe.411c3d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 9.2.WheTgQY.exe.411c3d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 9.2.WheTgQY.exe.411c3d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000009.00000002.2077441641.000000000411C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.2036673189.00000000043DE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe PID: 3948, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: WheTgQY.exe PID: 5456, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: schannel.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ntasn1.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ncrypt.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Section loaded: dpapi.dll | |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, iCcs8YPAkCV0etVwL9.cs | High entropy of concatenated method names: 'u9Eu1uSUKS', 'X3HuMrkaVY', 'icNuufihhU', 'arluHY9ghP', 'cIduySfnxL', 'l65uhWNKbL', 'Dispose', 'BAYQZ1t4MJ', 'BbWQiYfbuN', 'XFxQLDy4ny' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, w90A1jnMoPf4Br66m9.cs | High entropy of concatenated method names: 'akjOZ8JEdN', 'i8fOLCtmSK', 'bmuO2uX4Ac', 'gJ52oNpuBj', 'S9T2z9HWtZ', 'uCqOlYakR3', 'roWOpJnnt4', 'S7BO579Se9', 'cI5OAMwHcY', 'GDFOsnv25Y' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, kJCm3784MdIr1AhtcP.cs | High entropy of concatenated method names: 'G2W1c740n3', 'O3W1aJlKYj', 't3d18yya1r', 'MtI1NC6O1O', 'O1v1mS75We', 'tR01eltXtb', 'XHL1Jkwqu0', 'xNH1tZp5PT', 'zer1TXwIZv', 'er51nCTVV2' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, ua2Hibx6ZJxZHLkI9Q.cs | High entropy of concatenated method names: 'ukwM4yHtXq', 'VgVMow7fbV', 'p48QlRXELa', 'lbxQp67g6E', 'ixAMEFs6jL', 'RGXMapE1pw', 'LHWM3sarus', 'GOsM8RR4Qa', 'rnlMNPfsBA', 'cCXMvbhd0K' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, Ygu3V0U7WENZpiB0Rh.cs | High entropy of concatenated method names: 'ySC2WsowAC', 'sv72ijQ4UK', 'eGw26iHp2Z', 'Ypf2OjGADx', 'eNo2RBphWP', 'OAY6rUpdZG', 'Eti6xFxQUJ', 'Gxl6Pqc8ii', 'X1p64IBIiN', 'NFC6fYdHgu' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, kkyuEWbsq1ZCQwxdXQ.cs | High entropy of concatenated method names: 'zc7i8Zj4b6', 'J9jiN6plHO', 'O7uivxlZUT', 'HF1iIqYIfH', 'AQ7irTOqon', 'O7pixwbwwj', 'O16iPqHe0Q', 'dWdi4wDe2E', 'm8lifZKbk2', 'xNjioFLKnM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, aqyGOlBN8CM3jEJht0.cs | High entropy of concatenated method names: 'C1ZO06crM9', 'hJJOKy1ofn', 'NP5OgRhY8W', 'qXUOdgHUpH', 'X3AOYtaNYZ', 'SDOOSfbL5W', 'oZpO7d0KUZ', 'r91ObT03r6', 'PjVO9qS0fp', 'jE9OquDVuU' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, HMrRYozAd8caEdwjOH.cs | High entropy of concatenated method names: 'WvrjSreHnb', 'i7Ajb2r2lg', 'We2j9ZEbFP', 'rVHjUy3Ub6', 'nq4jmyiUp2', 'l4pjJXtA14', 'CaWjte75G4', 'crmjhs7Jwp', 'SUDj0x7yQZ', 'UgajKDqSCy' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, n3gWy0IkhZMqDGVwnx.cs | High entropy of concatenated method names: 'vZGMX9qPSP', 'RY7MCA1msi', 'ToString', 'I44MZZ3h44', 'SbSMi9MXS6', 'qp0MLC07TA', 'HXDM6rICkj', 'a8tM2Sn9Mj', 'j7QMOOdDXj', 'c5JMRN8yRt' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, y0d6quslK3NXUumYtW.cs | High entropy of concatenated method names: 'TZRpOkyuEW', 'dq1pRZCQwx', 'M2opXZfnX2', 'tKmpC2BciG', 'ry2p1v9ogu', 'QV0pF7WENZ', 'vdPcvCPNtSEk4NdTsN', 'jGwOYOKbQ04d0RXYdM', 'No9ppakQ4O', 'PVSpAlZNRk' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, UE0SrmplFAtSaQ8Im96.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Y25jElbAGt', 'dXTjadMZq3', 'UYlj30vMIO', 'wETj8u5aD7', 'uMTjNyLJey', 'qbpjvkC6DO', 't8TjIAUrlm' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, SmAv1s3xG5ELJWCDwm.cs | High entropy of concatenated method names: 'oLJkbnXnEn', 'Okek9gavU2', 'fEEkUot656', 'D1MkmVcBnf', 'cA1kJ1Stss', 'TD0ktTZEEE', 'hFOknyDknn', 'GX6kw33NMO', 'JOvkcuG767', 'h4bkEQDMOi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, MciGssqEFELlbQy2v9.cs | High entropy of concatenated method names: 'ipM6YWn7eh', 'ai3676Ti5d', 'djdLeVH5kx', 'wHpLJ1xKlC', 'cDGLt26Fjg', 'CSZLTskR5t', 'wusLn2968j', 'xkSLwFT82X', 'Yt7LBi5Pru', 'splLcw5ZPO' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, f9q9we5WEOkHCUbSS8.cs | High entropy of concatenated method names: 'etjg9dcBN', 'h2rdPnaEf', 'emYSDtjcX', 'GTZ7OBMwQ', 'BPv9tjrTf', 'Oh8qGdJor', 'fDHZWfiXMZuLhjEBy8', 'kSBwj0fHdCtIHLAdvi', 'peoQAmwKi', 'xYDj9cvQI' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, G8jNSB92oZfnX2HKm2.cs | High entropy of concatenated method names: 'v8xLdJDgZn', 'zVXLSQ5tIb', 'sRPLb34E7J', 'tm5L9jxnjh', 'O88L1IjPvi', 'pDMLFoJHcG', 'geeLMsMl3I', 'fT8LQcAONT', 't1BLuwr7LN', 'WGDLj6jKkS' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, soPyQMTbL8lM5TQHkR.cs | High entropy of concatenated method names: 'rkv2voGWH9', 'aaE2IHA3TQ', 'ghS2rH91eS', 'ToString', 'HLN2xdjW6Q', 'PRy2PJv09I', 'NbeqTKhmJVkFD3wWD1h', 'WROJPnh2dZkVxSyaxuB', 'udoCFEh6bC4pbjQGORM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, NMrfmOvdAmj7dFUB9s.cs | High entropy of concatenated method names: 'ToString', 'eiZFEss2Fs', 'uB6FmutTEE', 'EJoFebJiAc', 'P9iFJFByCl', 'fcDFtxbdmm', 'EK7FTtjtGg', 'ti4FnFXqMm', 'kpJFwleopV', 'skGFBBqkM6' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, T2jEttffFsbbJVuRWm.cs | High entropy of concatenated method names: 'LQtuU4ypSE', 'UioumWwjst', 'YDgueUbc4H', 'mvwuJHfFVw', 's7Wut9AdMd', 'o4CuTsVduI', 'K9uungejcl', 'HT1uwUOSpS', 'TdHuBNPMnG', 'Ktoucj3q2w' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, LfUsopiDSj17gx4YBa.cs | High entropy of concatenated method names: 'Dispose', 'mV0pfetVwL', 'fP05m30fUQ', 'yZeYHft58s', 'ELJpoSmffB', 'B0JpzRsTbA', 'ProcessDialogKey', 'OlI5l2jEtt', 'XFs5pbbJVu', 'kWm55JaNmi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, LxU94UppiMQcmvaDIT2.cs | High entropy of concatenated method names: 'rNcjoflIKs', 'UtBjznx90p', 'PQTHlYoFpa', 'EmTHpc9rQa', 'Sq0H5RYrGH', 'ctHHALnmY2', 'yJ7HsABjXn', 'P3WHWI1OZf', 'fRQHZD9AcZ', 'D88HiP9hqa' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, XSC45GRfM1SSKcDUtG.cs | High entropy of concatenated method names: 'S7dAWRW0as', 'SfyAZPdgjk', 'KtfAiUVQEH', 'AxrALKviK9', 'Du4A6NOEPT', 'KqnA2y3t0x', 'IaxAOCgR7X', 'a8KARfd0sS', 'ejDAGBFNKX', 's6RAXlAHKJ' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4611370.0.raw.unpack, O08or7psCSBfFZSdPeL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OnlVuFopnb', 'uhXVjORM2x', 'xLLVHLaOgE', 'zusVVCnq6N', 'JEbVyeTLD3', 'iUNVDG1u2A', 'VasVhCwWq5' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, iCcs8YPAkCV0etVwL9.cs | High entropy of concatenated method names: 'u9Eu1uSUKS', 'X3HuMrkaVY', 'icNuufihhU', 'arluHY9ghP', 'cIduySfnxL', 'l65uhWNKbL', 'Dispose', 'BAYQZ1t4MJ', 'BbWQiYfbuN', 'XFxQLDy4ny' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, w90A1jnMoPf4Br66m9.cs | High entropy of concatenated method names: 'akjOZ8JEdN', 'i8fOLCtmSK', 'bmuO2uX4Ac', 'gJ52oNpuBj', 'S9T2z9HWtZ', 'uCqOlYakR3', 'roWOpJnnt4', 'S7BO579Se9', 'cI5OAMwHcY', 'GDFOsnv25Y' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, kJCm3784MdIr1AhtcP.cs | High entropy of concatenated method names: 'G2W1c740n3', 'O3W1aJlKYj', 't3d18yya1r', 'MtI1NC6O1O', 'O1v1mS75We', 'tR01eltXtb', 'XHL1Jkwqu0', 'xNH1tZp5PT', 'zer1TXwIZv', 'er51nCTVV2' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, ua2Hibx6ZJxZHLkI9Q.cs | High entropy of concatenated method names: 'ukwM4yHtXq', 'VgVMow7fbV', 'p48QlRXELa', 'lbxQp67g6E', 'ixAMEFs6jL', 'RGXMapE1pw', 'LHWM3sarus', 'GOsM8RR4Qa', 'rnlMNPfsBA', 'cCXMvbhd0K' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, Ygu3V0U7WENZpiB0Rh.cs | High entropy of concatenated method names: 'ySC2WsowAC', 'sv72ijQ4UK', 'eGw26iHp2Z', 'Ypf2OjGADx', 'eNo2RBphWP', 'OAY6rUpdZG', 'Eti6xFxQUJ', 'Gxl6Pqc8ii', 'X1p64IBIiN', 'NFC6fYdHgu' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, kkyuEWbsq1ZCQwxdXQ.cs | High entropy of concatenated method names: 'zc7i8Zj4b6', 'J9jiN6plHO', 'O7uivxlZUT', 'HF1iIqYIfH', 'AQ7irTOqon', 'O7pixwbwwj', 'O16iPqHe0Q', 'dWdi4wDe2E', 'm8lifZKbk2', 'xNjioFLKnM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, aqyGOlBN8CM3jEJht0.cs | High entropy of concatenated method names: 'C1ZO06crM9', 'hJJOKy1ofn', 'NP5OgRhY8W', 'qXUOdgHUpH', 'X3AOYtaNYZ', 'SDOOSfbL5W', 'oZpO7d0KUZ', 'r91ObT03r6', 'PjVO9qS0fp', 'jE9OquDVuU' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, HMrRYozAd8caEdwjOH.cs | High entropy of concatenated method names: 'WvrjSreHnb', 'i7Ajb2r2lg', 'We2j9ZEbFP', 'rVHjUy3Ub6', 'nq4jmyiUp2', 'l4pjJXtA14', 'CaWjte75G4', 'crmjhs7Jwp', 'SUDj0x7yQZ', 'UgajKDqSCy' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, n3gWy0IkhZMqDGVwnx.cs | High entropy of concatenated method names: 'vZGMX9qPSP', 'RY7MCA1msi', 'ToString', 'I44MZZ3h44', 'SbSMi9MXS6', 'qp0MLC07TA', 'HXDM6rICkj', 'a8tM2Sn9Mj', 'j7QMOOdDXj', 'c5JMRN8yRt' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, y0d6quslK3NXUumYtW.cs | High entropy of concatenated method names: 'TZRpOkyuEW', 'dq1pRZCQwx', 'M2opXZfnX2', 'tKmpC2BciG', 'ry2p1v9ogu', 'QV0pF7WENZ', 'vdPcvCPNtSEk4NdTsN', 'jGwOYOKbQ04d0RXYdM', 'No9ppakQ4O', 'PVSpAlZNRk' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, UE0SrmplFAtSaQ8Im96.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Y25jElbAGt', 'dXTjadMZq3', 'UYlj30vMIO', 'wETj8u5aD7', 'uMTjNyLJey', 'qbpjvkC6DO', 't8TjIAUrlm' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, SmAv1s3xG5ELJWCDwm.cs | High entropy of concatenated method names: 'oLJkbnXnEn', 'Okek9gavU2', 'fEEkUot656', 'D1MkmVcBnf', 'cA1kJ1Stss', 'TD0ktTZEEE', 'hFOknyDknn', 'GX6kw33NMO', 'JOvkcuG767', 'h4bkEQDMOi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, MciGssqEFELlbQy2v9.cs | High entropy of concatenated method names: 'ipM6YWn7eh', 'ai3676Ti5d', 'djdLeVH5kx', 'wHpLJ1xKlC', 'cDGLt26Fjg', 'CSZLTskR5t', 'wusLn2968j', 'xkSLwFT82X', 'Yt7LBi5Pru', 'splLcw5ZPO' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, f9q9we5WEOkHCUbSS8.cs | High entropy of concatenated method names: 'etjg9dcBN', 'h2rdPnaEf', 'emYSDtjcX', 'GTZ7OBMwQ', 'BPv9tjrTf', 'Oh8qGdJor', 'fDHZWfiXMZuLhjEBy8', 'kSBwj0fHdCtIHLAdvi', 'peoQAmwKi', 'xYDj9cvQI' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, G8jNSB92oZfnX2HKm2.cs | High entropy of concatenated method names: 'v8xLdJDgZn', 'zVXLSQ5tIb', 'sRPLb34E7J', 'tm5L9jxnjh', 'O88L1IjPvi', 'pDMLFoJHcG', 'geeLMsMl3I', 'fT8LQcAONT', 't1BLuwr7LN', 'WGDLj6jKkS' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, soPyQMTbL8lM5TQHkR.cs | High entropy of concatenated method names: 'rkv2voGWH9', 'aaE2IHA3TQ', 'ghS2rH91eS', 'ToString', 'HLN2xdjW6Q', 'PRy2PJv09I', 'NbeqTKhmJVkFD3wWD1h', 'WROJPnh2dZkVxSyaxuB', 'udoCFEh6bC4pbjQGORM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, NMrfmOvdAmj7dFUB9s.cs | High entropy of concatenated method names: 'ToString', 'eiZFEss2Fs', 'uB6FmutTEE', 'EJoFebJiAc', 'P9iFJFByCl', 'fcDFtxbdmm', 'EK7FTtjtGg', 'ti4FnFXqMm', 'kpJFwleopV', 'skGFBBqkM6' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, T2jEttffFsbbJVuRWm.cs | High entropy of concatenated method names: 'LQtuU4ypSE', 'UioumWwjst', 'YDgueUbc4H', 'mvwuJHfFVw', 's7Wut9AdMd', 'o4CuTsVduI', 'K9uungejcl', 'HT1uwUOSpS', 'TdHuBNPMnG', 'Ktoucj3q2w' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, LfUsopiDSj17gx4YBa.cs | High entropy of concatenated method names: 'Dispose', 'mV0pfetVwL', 'fP05m30fUQ', 'yZeYHft58s', 'ELJpoSmffB', 'B0JpzRsTbA', 'ProcessDialogKey', 'OlI5l2jEtt', 'XFs5pbbJVu', 'kWm55JaNmi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, LxU94UppiMQcmvaDIT2.cs | High entropy of concatenated method names: 'rNcjoflIKs', 'UtBjznx90p', 'PQTHlYoFpa', 'EmTHpc9rQa', 'Sq0H5RYrGH', 'ctHHALnmY2', 'yJ7HsABjXn', 'P3WHWI1OZf', 'fRQHZD9AcZ', 'D88HiP9hqa' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, XSC45GRfM1SSKcDUtG.cs | High entropy of concatenated method names: 'S7dAWRW0as', 'SfyAZPdgjk', 'KtfAiUVQEH', 'AxrALKviK9', 'Du4A6NOEPT', 'KqnA2y3t0x', 'IaxAOCgR7X', 'a8KARfd0sS', 'ejDAGBFNKX', 's6RAXlAHKJ' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.4698990.2.raw.unpack, O08or7psCSBfFZSdPeL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OnlVuFopnb', 'uhXVjORM2x', 'xLLVHLaOgE', 'zusVVCnq6N', 'JEbVyeTLD3', 'iUNVDG1u2A', 'VasVhCwWq5' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, iCcs8YPAkCV0etVwL9.cs | High entropy of concatenated method names: 'u9Eu1uSUKS', 'X3HuMrkaVY', 'icNuufihhU', 'arluHY9ghP', 'cIduySfnxL', 'l65uhWNKbL', 'Dispose', 'BAYQZ1t4MJ', 'BbWQiYfbuN', 'XFxQLDy4ny' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, w90A1jnMoPf4Br66m9.cs | High entropy of concatenated method names: 'akjOZ8JEdN', 'i8fOLCtmSK', 'bmuO2uX4Ac', 'gJ52oNpuBj', 'S9T2z9HWtZ', 'uCqOlYakR3', 'roWOpJnnt4', 'S7BO579Se9', 'cI5OAMwHcY', 'GDFOsnv25Y' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, kJCm3784MdIr1AhtcP.cs | High entropy of concatenated method names: 'G2W1c740n3', 'O3W1aJlKYj', 't3d18yya1r', 'MtI1NC6O1O', 'O1v1mS75We', 'tR01eltXtb', 'XHL1Jkwqu0', 'xNH1tZp5PT', 'zer1TXwIZv', 'er51nCTVV2' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, ua2Hibx6ZJxZHLkI9Q.cs | High entropy of concatenated method names: 'ukwM4yHtXq', 'VgVMow7fbV', 'p48QlRXELa', 'lbxQp67g6E', 'ixAMEFs6jL', 'RGXMapE1pw', 'LHWM3sarus', 'GOsM8RR4Qa', 'rnlMNPfsBA', 'cCXMvbhd0K' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, Ygu3V0U7WENZpiB0Rh.cs | High entropy of concatenated method names: 'ySC2WsowAC', 'sv72ijQ4UK', 'eGw26iHp2Z', 'Ypf2OjGADx', 'eNo2RBphWP', 'OAY6rUpdZG', 'Eti6xFxQUJ', 'Gxl6Pqc8ii', 'X1p64IBIiN', 'NFC6fYdHgu' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, kkyuEWbsq1ZCQwxdXQ.cs | High entropy of concatenated method names: 'zc7i8Zj4b6', 'J9jiN6plHO', 'O7uivxlZUT', 'HF1iIqYIfH', 'AQ7irTOqon', 'O7pixwbwwj', 'O16iPqHe0Q', 'dWdi4wDe2E', 'm8lifZKbk2', 'xNjioFLKnM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, aqyGOlBN8CM3jEJht0.cs | High entropy of concatenated method names: 'C1ZO06crM9', 'hJJOKy1ofn', 'NP5OgRhY8W', 'qXUOdgHUpH', 'X3AOYtaNYZ', 'SDOOSfbL5W', 'oZpO7d0KUZ', 'r91ObT03r6', 'PjVO9qS0fp', 'jE9OquDVuU' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, HMrRYozAd8caEdwjOH.cs | High entropy of concatenated method names: 'WvrjSreHnb', 'i7Ajb2r2lg', 'We2j9ZEbFP', 'rVHjUy3Ub6', 'nq4jmyiUp2', 'l4pjJXtA14', 'CaWjte75G4', 'crmjhs7Jwp', 'SUDj0x7yQZ', 'UgajKDqSCy' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, n3gWy0IkhZMqDGVwnx.cs | High entropy of concatenated method names: 'vZGMX9qPSP', 'RY7MCA1msi', 'ToString', 'I44MZZ3h44', 'SbSMi9MXS6', 'qp0MLC07TA', 'HXDM6rICkj', 'a8tM2Sn9Mj', 'j7QMOOdDXj', 'c5JMRN8yRt' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, y0d6quslK3NXUumYtW.cs | High entropy of concatenated method names: 'TZRpOkyuEW', 'dq1pRZCQwx', 'M2opXZfnX2', 'tKmpC2BciG', 'ry2p1v9ogu', 'QV0pF7WENZ', 'vdPcvCPNtSEk4NdTsN', 'jGwOYOKbQ04d0RXYdM', 'No9ppakQ4O', 'PVSpAlZNRk' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, UE0SrmplFAtSaQ8Im96.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Y25jElbAGt', 'dXTjadMZq3', 'UYlj30vMIO', 'wETj8u5aD7', 'uMTjNyLJey', 'qbpjvkC6DO', 't8TjIAUrlm' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, SmAv1s3xG5ELJWCDwm.cs | High entropy of concatenated method names: 'oLJkbnXnEn', 'Okek9gavU2', 'fEEkUot656', 'D1MkmVcBnf', 'cA1kJ1Stss', 'TD0ktTZEEE', 'hFOknyDknn', 'GX6kw33NMO', 'JOvkcuG767', 'h4bkEQDMOi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, MciGssqEFELlbQy2v9.cs | High entropy of concatenated method names: 'ipM6YWn7eh', 'ai3676Ti5d', 'djdLeVH5kx', 'wHpLJ1xKlC', 'cDGLt26Fjg', 'CSZLTskR5t', 'wusLn2968j', 'xkSLwFT82X', 'Yt7LBi5Pru', 'splLcw5ZPO' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, f9q9we5WEOkHCUbSS8.cs | High entropy of concatenated method names: 'etjg9dcBN', 'h2rdPnaEf', 'emYSDtjcX', 'GTZ7OBMwQ', 'BPv9tjrTf', 'Oh8qGdJor', 'fDHZWfiXMZuLhjEBy8', 'kSBwj0fHdCtIHLAdvi', 'peoQAmwKi', 'xYDj9cvQI' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, G8jNSB92oZfnX2HKm2.cs | High entropy of concatenated method names: 'v8xLdJDgZn', 'zVXLSQ5tIb', 'sRPLb34E7J', 'tm5L9jxnjh', 'O88L1IjPvi', 'pDMLFoJHcG', 'geeLMsMl3I', 'fT8LQcAONT', 't1BLuwr7LN', 'WGDLj6jKkS' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, soPyQMTbL8lM5TQHkR.cs | High entropy of concatenated method names: 'rkv2voGWH9', 'aaE2IHA3TQ', 'ghS2rH91eS', 'ToString', 'HLN2xdjW6Q', 'PRy2PJv09I', 'NbeqTKhmJVkFD3wWD1h', 'WROJPnh2dZkVxSyaxuB', 'udoCFEh6bC4pbjQGORM' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, NMrfmOvdAmj7dFUB9s.cs | High entropy of concatenated method names: 'ToString', 'eiZFEss2Fs', 'uB6FmutTEE', 'EJoFebJiAc', 'P9iFJFByCl', 'fcDFtxbdmm', 'EK7FTtjtGg', 'ti4FnFXqMm', 'kpJFwleopV', 'skGFBBqkM6' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, T2jEttffFsbbJVuRWm.cs | High entropy of concatenated method names: 'LQtuU4ypSE', 'UioumWwjst', 'YDgueUbc4H', 'mvwuJHfFVw', 's7Wut9AdMd', 'o4CuTsVduI', 'K9uungejcl', 'HT1uwUOSpS', 'TdHuBNPMnG', 'Ktoucj3q2w' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, LfUsopiDSj17gx4YBa.cs | High entropy of concatenated method names: 'Dispose', 'mV0pfetVwL', 'fP05m30fUQ', 'yZeYHft58s', 'ELJpoSmffB', 'B0JpzRsTbA', 'ProcessDialogKey', 'OlI5l2jEtt', 'XFs5pbbJVu', 'kWm55JaNmi' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, LxU94UppiMQcmvaDIT2.cs | High entropy of concatenated method names: 'rNcjoflIKs', 'UtBjznx90p', 'PQTHlYoFpa', 'EmTHpc9rQa', 'Sq0H5RYrGH', 'ctHHALnmY2', 'yJ7HsABjXn', 'P3WHWI1OZf', 'fRQHZD9AcZ', 'D88HiP9hqa' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, XSC45GRfM1SSKcDUtG.cs | High entropy of concatenated method names: 'S7dAWRW0as', 'SfyAZPdgjk', 'KtfAiUVQEH', 'AxrALKviK9', 'Du4A6NOEPT', 'KqnA2y3t0x', 'IaxAOCgR7X', 'a8KARfd0sS', 'ejDAGBFNKX', 's6RAXlAHKJ' |
Source: 0.2.T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe.b840000.4.raw.unpack, O08or7psCSBfFZSdPeL.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OnlVuFopnb', 'uhXVjORM2x', 'xLLVHLaOgE', 'zusVVCnq6N', 'JEbVyeTLD3', 'iUNVDG1u2A', 'VasVhCwWq5' |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239883 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239765 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239651 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239546 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239435 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239328 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239219 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239109 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238883 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238688 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238463 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238156 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237989 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237859 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237664 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239812 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239702 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239589 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239469 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239360 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239247 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239137 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238992 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238504 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238384 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238278 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238170 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238047 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 237935 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599890 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599560 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597797 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597465 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597234 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597125 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597015 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596906 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596797 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596687 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596575 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596469 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596359 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596250 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596140 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596030 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595922 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595812 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595703 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595594 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595375 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595265 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595042 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594922 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594812 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594703 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594594 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599890 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599773 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599671 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599562 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599453 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599343 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599231 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599125 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599015 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598903 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598797 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598687 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598576 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598468 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598359 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598250 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598140 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598031 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597922 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597812 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597703 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597593 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597484 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597375 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597265 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597156 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597047 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596937 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596822 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596718 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596609 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596491 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596346 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596218 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596108 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595997 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595890 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595781 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595671 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595562 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595453 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595343 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595234 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595125 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595015 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594906 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594797 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594687 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594578 | |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -240000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239883s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239651s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239435s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -239000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -238883s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -238688s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -238463s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -238156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -237989s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -237859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4324 | Thread sleep time: -237664s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 4088 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1680 | Thread sleep count: 6929 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3872 | Thread sleep time: -4611686018427385s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5740 | Thread sleep count: 410 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6256 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5328 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 764 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -13835058055282155s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -240000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239812s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239702s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239589s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239469s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239360s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239247s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -239137s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238992s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238504s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238384s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238278s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238170s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -238047s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7212 | Thread sleep time: -237935s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -26747778906878833s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7360 | Thread sleep count: 2117 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7360 | Thread sleep count: 7730 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599560s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -599000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -598015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597465s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -597015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596575s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596469s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -596030s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595922s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595594s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595265s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -595042s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -594922s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -594812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -594703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe TID: 7316 | Thread sleep time: -594594s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep count: 33 > 30 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -30437127721620741s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599890s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7484 | Thread sleep count: 8332 > 30 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7484 | Thread sleep count: 1526 > 30 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599773s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599671s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599343s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599231s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599125s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -599015s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598903s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598797s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598576s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598468s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598359s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598250s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598140s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -598031s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597922s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597812s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597703s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597593s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597484s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597375s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597265s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597156s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -597047s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596937s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596822s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596718s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596609s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596491s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596346s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596218s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -596108s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595997s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595890s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595671s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595343s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595234s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595125s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -595015s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -594906s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -594797s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -594687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe TID: 7480 | Thread sleep time: -594578s >= -30000s | |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239883 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239765 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239651 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239546 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239435 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239328 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239219 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239109 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 239000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238883 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238688 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238463 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 238156 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237989 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237859 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 237664 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239812 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239702 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239589 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239469 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239360 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239247 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 239137 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238992 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238504 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238384 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238278 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238170 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 238047 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 237935 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599890 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599560 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597797 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597465 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597344 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597234 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597125 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 597015 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596906 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596797 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596687 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596575 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596469 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596359 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596250 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596140 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 596030 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595922 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595812 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595703 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595594 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595375 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595265 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 595042 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594922 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594812 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594703 | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Thread delayed: delay time: 594594 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599890 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599773 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599671 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599562 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599453 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599343 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599231 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599125 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 599015 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598903 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598797 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598687 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598576 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598468 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598359 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598250 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598140 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 598031 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597922 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597812 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597703 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597593 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597484 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597375 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597265 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597156 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 597047 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596937 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596822 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596718 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596609 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596491 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596346 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596218 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 596108 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595997 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595890 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595781 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595671 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595562 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595453 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595343 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595234 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595125 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 595015 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594906 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594797 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594687 | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Thread delayed: delay time: 594578 | |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: WheTgQY.exe, 00000009.00000002.2081548688.0000000007D63000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\5# |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 0000000A.00000002.4485070133.0000000000D99000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllH |
Source: T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe, 00000000.00000002.2043053754.0000000007329000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}{ |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: WheTgQY.exe, 00000010.00000002.4485590144.0000000000B57000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: WheTgQY.exe, 00000009.00000002.2081548688.0000000007D63000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003884000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: WheTgQY.exe, 00000010.00000002.4500335062.0000000003BA3000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Users\user\AppData\Roaming\WheTgQY.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Users\user\AppData\Roaming\WheTgQY.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WheTgQY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |