Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: Bank Transfer Form.exe, 00000000.00000002.1712733368.0000000002D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Bank Transfer Form.exe | String found in binary or memory: http://tempuri.org/DataTableUsers.xsd |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003281000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://varders.kozow.com:8081 |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fonts.com |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.tiro.com |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.typography.netD |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: Bank Transfer Form.exe, 00000000.00000002.1718877847.0000000007242000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:445817%0D%0ADate%20a |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003446000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.000000000338C000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003477000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003437000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003441000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enlB |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003341000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.00000000032D1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: Bank Transfer Form.exe, 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.00000000032D1000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.00000000032FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189 |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003368000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003341000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.00000000032FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$ |
Source: Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004505000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043AF000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043D6000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.000000000338C000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004553000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004629000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004361000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004368000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043B2000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004604000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.000000000433D000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000044E1000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.000000000450C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004505000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043AF000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043D6000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4140066639.000000000338C000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004553000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004629000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004361000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004368000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000043B2000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.0000000004604000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.000000000433D000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.00000000044E1000.00000004.00000800.00020000.00000000.sdmp, Bank Transfer Form.exe, 00000003.00000002.4142924007.000000000450C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003477000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/ |
Source: Bank Transfer Form.exe, 00000003.00000002.4140066639.0000000003472000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/lB |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0114E044 | 0_2_0114E044 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_05FAF0A9 | 0_2_05FAF0A9 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_05FA0A80 | 0_2_05FA0A80 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_05FA0A70 | 0_2_05FA0A70 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07777712 | 0_2_07777712 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07775170 | 0_2_07775170 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07770A20 | 0_2_07770A20 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07775460 | 0_2_07775460 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07775451 | 0_2_07775451 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777C438 | 0_2_0777C438 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777C429 | 0_2_0777C429 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07775160 | 0_2_07775160 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_077741F0 | 0_2_077741F0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_077741DF | 0_2_077741DF |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_077741B9 | 0_2_077741B9 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777C000 | 0_2_0777C000 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777DF18 | 0_2_0777DF18 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07772BF8 | 0_2_07772BF8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_07770A10 | 0_2_07770A10 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777C870 | 0_2_0777C870 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777C860 | 0_2_0777C860 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0777E848 | 0_2_0777E848 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 0_2_0F273660 | 0_2_0F273660 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_01807118 | 3_2_01807118 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180C147 | 3_2_0180C147 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180A088 | 3_2_0180A088 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_01805362 | 3_2_01805362 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180D278 | 3_2_0180D278 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180C468 | 3_2_0180C468 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180C738 | 3_2_0180C738 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180E988 | 3_2_0180E988 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_018069A0 | 3_2_018069A0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_018029E0 | 3_2_018029E0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180CA08 | 3_2_0180CA08 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180CCD8 | 3_2_0180CCD8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180CFAB | 3_2_0180CFAB |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_01803E09 | 3_2_01803E09 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180F631 | 3_2_0180F631 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180E97B | 3_2_0180E97B |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_0180FA88 | 3_2_0180FA88 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F31E80 | 3_2_06F31E80 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F317A0 | 3_2_06F317A0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F39C70 | 3_2_06F39C70 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F39548 | 3_2_06F39548 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F30B30 | 3_2_06F30B30 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F35028 | 3_2_06F35028 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F32968 | 3_2_06F32968 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3E6B0 | 3_2_06F3E6B0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3E6AF | 3_2_06F3E6AF |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F31E70 | 3_2_06F31E70 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3DE00 | 3_2_06F3DE00 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3178F | 3_2_06F3178F |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3EF60 | 3_2_06F3EF60 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3EF51 | 3_2_06F3EF51 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3CCA0 | 3_2_06F3CCA0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3FC68 | 3_2_06F3FC68 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F39C6D | 3_2_06F39C6D |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3DDFF | 3_2_06F3DDFF |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3D550 | 3_2_06F3D550 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3D540 | 3_2_06F3D540 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3EAF8 | 3_2_06F3EAF8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3E258 | 3_2_06F3E258 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3E249 | 3_2_06F3E249 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3F3B8 | 3_2_06F3F3B8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F38BA0 | 3_2_06F38BA0 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F38B90 | 3_2_06F38B90 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F30B20 | 3_2_06F30B20 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F39328 | 3_2_06F39328 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3EB08 | 3_2_06F3EB08 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3D0F8 | 3_2_06F3D0F8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F30040 | 3_2_06F30040 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3F810 | 3_2_06F3F810 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F35018 | 3_2_06F35018 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3F801 | 3_2_06F3F801 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F30006 | 3_2_06F30006 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3D9A8 | 3_2_06F3D9A8 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3D999 | 3_2_06F3D999 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Code function: 3_2_06F3295A | 3_2_06F3295A |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.4990830.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.Bank Transfer Form.exe.4990830.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.Bank Transfer Form.exe.4990830.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.3ddcbf0.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Bank Transfer Form.exe.4990830.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 3.2.Bank Transfer Form.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.4990830.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 3.2.Bank Transfer Form.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 3.2.Bank Transfer Form.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Bank Transfer Form.exe.4990830.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000003.00000002.4138633105.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1713811273.0000000003D81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1713811273.000000000464E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: Bank Transfer Form.exe PID: 7404, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: Bank Transfer Form.exe PID: 7596, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, YRJCD4GuTkTB5AFtUh.cs | High entropy of concatenated method names: 'sUteCUKxOF', 'aHYeYIgr7H', 'y6lefvIT1U', 'KWDe2CZ228', 'PZZewcLtKa', 'hnreqRgKGG', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, FyOPAW54oZ0b7HNW4y.cs | High entropy of concatenated method names: 'Dispose', 'U409luscwt', 'rYJkBqMk8m', 'a8al88GfCG', 'hFX9Gb9sHS', 'vgF9zP5qcW', 'ProcessDialogKey', 'iyok7A8ZRt', 'DQ2k9cNhrw', 'gCZkkGRJCD' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, WPHP2SbJjmZSALkB5D.cs | High entropy of concatenated method names: 'g0F5EsE8Ix', 'c0K5IoGB8X', 'yRK5tT8JaV', 'Cw95Lv2Rf2', 'n4m58kF2vq', 'uZq5HLNdOo', 'vqB5Vrf27o', 'jSk5WIHugE', 'EOl5lAFs5c', 'W265Gk4CB3' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, OrbTnwVH9840uscwtY.cs | High entropy of concatenated method names: 'IIqwU77tpg', 'KqtwaCr0VR', 'ti1wwI3P2W', 'khywdw3Duf', 'mqJw3llEb7', 'Cwow4GQXaq', 'Dispose', 'VZWAhW8Bb3', 'XtAA5gBYG4', 'HIjACjTA6V' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, DIv3B497lwTEGfxJNnW.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'LdgeoQj9PL', 'Qy8e00HZYo', 'pm3epIkOxU', 'yDIeEhSxhi', 'nBdeILVKnn', 'Vc0etMi0rp', 'MZTeLgZqkr' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, GK3rb8Xx6FpRmLh2PZ.cs | High entropy of concatenated method names: 'E8426mT4SH', 'QsQ2SW2wxt', 'UnO2M8H4pW', 'DUp2DdRPyM', 'qEk2vUkFBu', 'gOs2x9bYXE', 'rR22mCUorV', 'JQ02bhcOYC', 'Mft2iulPXg', 'O5D21vpN1J' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, sy4xRxkBIgUYZjXBH8.cs | High entropy of concatenated method names: 'FDHMYKxYl', 'SOADinu0w', 'y21xQRAE9', 'vZimVoS0d', 'whTi74ctC', 'JYB1NfXIE', 'kDPevhZdyn7xh0J0RH', 'pnQSHjsS4yxDye4ZZa', 'u7PALJ4ku', 'ydVe0tljk' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, cNTAxyLngQ4wmnErdU.cs | High entropy of concatenated method names: 'HHVaKngIer', 'm7jausYccb', 'ToString', 'PlZahnIi2n', 't8sa52aUEV', 'pe2aC3JocW', 'wIdaYy18LW', 'VGbafGUjqg', 'to8a2ORRY4', 'Bjcaq0P3O5' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, rSACETqoHL0qafdKnG.cs | High entropy of concatenated method names: 'nkBQJ3iqmP', 'smOQhT0OPC', 'kIoQ5eQBZJ', 'nuVQC7eJgI', 'NInQYXP5cB', 'XEPQfWnMc9', 'U0ZQ25ZRQy', 'rvkQqPXdMW', 'TYQQTMhtK9', 'j59QKhm4Ef' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, lg884FPT14t8JDBNJj.cs | High entropy of concatenated method names: 'IBqfJx6MYO', 'cHCf5orYJH', 'F6MfYThPpJ', 'SUTf2aaHO0', 'u5xfqfhXfn', 'wXAY8JZODN', 'MfoYHBfSZj', 'ORQYVKqaCt', 'OOgYWG2TPL', 'ApfYl5w9pu' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, fafNrWNPmosQBQ9Hyh.cs | High entropy of concatenated method names: 'T9W92PHP2S', 'ejm9qZSALk', 'dLQ9KeObhS', 'SfT9ufWxS9', 'h9J9UerTg8', 'U4F9jT14t8', 'hryUc55iG5GAVx4FMr', 'hbwGACznxJgtRrXIhn', 'nCK995Y4VY', 'Oq79QxfQnw' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, W0luOeHPpUUnD0Gi9F.cs | High entropy of concatenated method names: 'SwjaW25Zr4', 'OZfaGRk12k', 'KNZA7iSVf6', 'IA2A9wvvfb', 'scqaohg2os', 'wtFa03K6PC', 'BZgapUtAA2', 'OC1aE12rG0', 'kF1aIkf2rO', 'R2Fatt9krh' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, sIYM2V99T3XKebu3Mfs.cs | High entropy of concatenated method names: 'Ln5eGFQVQw', 'EEiezM3X3G', 'XwXd7VqNCh', 'zMed9CMwsV', 'rRydkFDmSs', 'E8pdQOBm7K', 'sWrdNtgnlu', 'cdXdJ1p2Ey', 'zKRdheKVn6', 'ckad5Z4nNB' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, JaYZBb9Noi2bbtHjoAV.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'XF5ywKwRrJ', 'hD8yeOFWw8', 'uCQyd08j6L', 'erQyyfb71j', 'pyZy35JuvO', 'yJIyZ7GTmb', 'AsUy4G1o5A' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, XxS9LU1e3iUikC9Jer.cs | High entropy of concatenated method names: 'noiYvJ3g4i', 'daAYmUe5HV', 'KJICgbYHZ3', 'ji8CFa0fPf', 'lRmCRtQfvt', 'TisCcV9wHB', 'skRCsp6xyR', 'HmtCOVhdIu', 'kH4CXQDJuU', 'jg7CnaG1ti' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, DgcOPfs939iFMF7LnU.cs | High entropy of concatenated method names: 'AME2hBpFvu', 'UyR2C75sWm', 'w8M2fj5Z12', 'nJpfGOBPrU', 'fd3fz8TlJC', 'DXP27Id0Fg', 'hxy29FH72S', 'pZB2kgfDsI', 'iAh2Qi3QiX', 'qTp2N0ZrBK' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, OA8ZRtlmQ2cNhrw5CZ.cs | High entropy of concatenated method names: 'YRTwPPVhbe', 'd5WwBytxQ2', 'n3bwglwFvq', 'rqowFkq3Yn', 's0vwRbXecV', 'yNRwcE5kQ4', 'LgVwskrOqf', 'XOvwOo6Nik', 'z5lwXrejEE', 'ppDwnfNKAu' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, MA9tcoCn4p8ebb7jyP.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'cRqkl7YYrM', 'aT2kGpEgd6', 'amNkzHMhTM', 'UA4Q74qZwB', 'S1EQ9uQ8K1', 'eExQk2iek6', 'YVKQQqDLj5', 'WyBRQCjIsT01lbOWdIw' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, SqAFRrEyHODwOt21AL.cs | High entropy of concatenated method names: 'CXTUnxre4x', 'YX0U0ywSWh', 'S5wUEILNgQ', 'wqEUIOxlSm', 'w5FUBS96No', 'wfWUgomDRf', 'tQUUFOG15Z', 'gSrURajbD3', 'jIuUcFDORK', 'Qh4UsMo3q3' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, L4apYNiLQeObhStfTf.cs | High entropy of concatenated method names: 'RG6CDNOs43', 'qAoCxCWgI5', 'AGvCb4m0wo', 'OvfCiVlWuW', 'XrWCU3oYYx', 'N0BCjORV62', 'Q1qCaRKuHd', 'I7LCAKUWdL', 'MipCwGTrAj', 'JnECeMCPSX' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, DikMSDzLh1GP3ebiqj.cs | High entropy of concatenated method names: 'qDrexV8BFw', 'JIwebSbjbZ', 'Svnei2mcnK', 'Y4MePdS9qh', 'n6MeBDxgll', 'DqMeF2Rv5w', 'BYWeRHZbW6', 'I6ee4mJ4C9', 'FCte6f6lSH', 'LjYeSy2JQP' |
Source: 0.2.Bank Transfer Form.exe.b990000.6.raw.unpack, GOdDuQpxLDLFynigs0.cs | High entropy of concatenated method names: 'hQJrbb9RBt', 'IYkriJrehr', 'NHQrPtUKce', 'w3irBLfbTT', 'E7prFmd3eY', 'gRsrR4dHEM', 'IQCrsBVaQ3', 'vq8rODnL5f', 'MqtrntPDlR', 'ikkro2aybS' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, YRJCD4GuTkTB5AFtUh.cs | High entropy of concatenated method names: 'sUteCUKxOF', 'aHYeYIgr7H', 'y6lefvIT1U', 'KWDe2CZ228', 'PZZewcLtKa', 'hnreqRgKGG', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, FyOPAW54oZ0b7HNW4y.cs | High entropy of concatenated method names: 'Dispose', 'U409luscwt', 'rYJkBqMk8m', 'a8al88GfCG', 'hFX9Gb9sHS', 'vgF9zP5qcW', 'ProcessDialogKey', 'iyok7A8ZRt', 'DQ2k9cNhrw', 'gCZkkGRJCD' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, WPHP2SbJjmZSALkB5D.cs | High entropy of concatenated method names: 'g0F5EsE8Ix', 'c0K5IoGB8X', 'yRK5tT8JaV', 'Cw95Lv2Rf2', 'n4m58kF2vq', 'uZq5HLNdOo', 'vqB5Vrf27o', 'jSk5WIHugE', 'EOl5lAFs5c', 'W265Gk4CB3' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, OrbTnwVH9840uscwtY.cs | High entropy of concatenated method names: 'IIqwU77tpg', 'KqtwaCr0VR', 'ti1wwI3P2W', 'khywdw3Duf', 'mqJw3llEb7', 'Cwow4GQXaq', 'Dispose', 'VZWAhW8Bb3', 'XtAA5gBYG4', 'HIjACjTA6V' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, DIv3B497lwTEGfxJNnW.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'LdgeoQj9PL', 'Qy8e00HZYo', 'pm3epIkOxU', 'yDIeEhSxhi', 'nBdeILVKnn', 'Vc0etMi0rp', 'MZTeLgZqkr' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, GK3rb8Xx6FpRmLh2PZ.cs | High entropy of concatenated method names: 'E8426mT4SH', 'QsQ2SW2wxt', 'UnO2M8H4pW', 'DUp2DdRPyM', 'qEk2vUkFBu', 'gOs2x9bYXE', 'rR22mCUorV', 'JQ02bhcOYC', 'Mft2iulPXg', 'O5D21vpN1J' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, sy4xRxkBIgUYZjXBH8.cs | High entropy of concatenated method names: 'FDHMYKxYl', 'SOADinu0w', 'y21xQRAE9', 'vZimVoS0d', 'whTi74ctC', 'JYB1NfXIE', 'kDPevhZdyn7xh0J0RH', 'pnQSHjsS4yxDye4ZZa', 'u7PALJ4ku', 'ydVe0tljk' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, cNTAxyLngQ4wmnErdU.cs | High entropy of concatenated method names: 'HHVaKngIer', 'm7jausYccb', 'ToString', 'PlZahnIi2n', 't8sa52aUEV', 'pe2aC3JocW', 'wIdaYy18LW', 'VGbafGUjqg', 'to8a2ORRY4', 'Bjcaq0P3O5' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, rSACETqoHL0qafdKnG.cs | High entropy of concatenated method names: 'nkBQJ3iqmP', 'smOQhT0OPC', 'kIoQ5eQBZJ', 'nuVQC7eJgI', 'NInQYXP5cB', 'XEPQfWnMc9', 'U0ZQ25ZRQy', 'rvkQqPXdMW', 'TYQQTMhtK9', 'j59QKhm4Ef' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, lg884FPT14t8JDBNJj.cs | High entropy of concatenated method names: 'IBqfJx6MYO', 'cHCf5orYJH', 'F6MfYThPpJ', 'SUTf2aaHO0', 'u5xfqfhXfn', 'wXAY8JZODN', 'MfoYHBfSZj', 'ORQYVKqaCt', 'OOgYWG2TPL', 'ApfYl5w9pu' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, fafNrWNPmosQBQ9Hyh.cs | High entropy of concatenated method names: 'T9W92PHP2S', 'ejm9qZSALk', 'dLQ9KeObhS', 'SfT9ufWxS9', 'h9J9UerTg8', 'U4F9jT14t8', 'hryUc55iG5GAVx4FMr', 'hbwGACznxJgtRrXIhn', 'nCK995Y4VY', 'Oq79QxfQnw' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, W0luOeHPpUUnD0Gi9F.cs | High entropy of concatenated method names: 'SwjaW25Zr4', 'OZfaGRk12k', 'KNZA7iSVf6', 'IA2A9wvvfb', 'scqaohg2os', 'wtFa03K6PC', 'BZgapUtAA2', 'OC1aE12rG0', 'kF1aIkf2rO', 'R2Fatt9krh' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, sIYM2V99T3XKebu3Mfs.cs | High entropy of concatenated method names: 'Ln5eGFQVQw', 'EEiezM3X3G', 'XwXd7VqNCh', 'zMed9CMwsV', 'rRydkFDmSs', 'E8pdQOBm7K', 'sWrdNtgnlu', 'cdXdJ1p2Ey', 'zKRdheKVn6', 'ckad5Z4nNB' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, JaYZBb9Noi2bbtHjoAV.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'XF5ywKwRrJ', 'hD8yeOFWw8', 'uCQyd08j6L', 'erQyyfb71j', 'pyZy35JuvO', 'yJIyZ7GTmb', 'AsUy4G1o5A' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, XxS9LU1e3iUikC9Jer.cs | High entropy of concatenated method names: 'noiYvJ3g4i', 'daAYmUe5HV', 'KJICgbYHZ3', 'ji8CFa0fPf', 'lRmCRtQfvt', 'TisCcV9wHB', 'skRCsp6xyR', 'HmtCOVhdIu', 'kH4CXQDJuU', 'jg7CnaG1ti' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, DgcOPfs939iFMF7LnU.cs | High entropy of concatenated method names: 'AME2hBpFvu', 'UyR2C75sWm', 'w8M2fj5Z12', 'nJpfGOBPrU', 'fd3fz8TlJC', 'DXP27Id0Fg', 'hxy29FH72S', 'pZB2kgfDsI', 'iAh2Qi3QiX', 'qTp2N0ZrBK' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, OA8ZRtlmQ2cNhrw5CZ.cs | High entropy of concatenated method names: 'YRTwPPVhbe', 'd5WwBytxQ2', 'n3bwglwFvq', 'rqowFkq3Yn', 's0vwRbXecV', 'yNRwcE5kQ4', 'LgVwskrOqf', 'XOvwOo6Nik', 'z5lwXrejEE', 'ppDwnfNKAu' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, MA9tcoCn4p8ebb7jyP.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'cRqkl7YYrM', 'aT2kGpEgd6', 'amNkzHMhTM', 'UA4Q74qZwB', 'S1EQ9uQ8K1', 'eExQk2iek6', 'YVKQQqDLj5', 'WyBRQCjIsT01lbOWdIw' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, SqAFRrEyHODwOt21AL.cs | High entropy of concatenated method names: 'CXTUnxre4x', 'YX0U0ywSWh', 'S5wUEILNgQ', 'wqEUIOxlSm', 'w5FUBS96No', 'wfWUgomDRf', 'tQUUFOG15Z', 'gSrURajbD3', 'jIuUcFDORK', 'Qh4UsMo3q3' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, L4apYNiLQeObhStfTf.cs | High entropy of concatenated method names: 'RG6CDNOs43', 'qAoCxCWgI5', 'AGvCb4m0wo', 'OvfCiVlWuW', 'XrWCU3oYYx', 'N0BCjORV62', 'Q1qCaRKuHd', 'I7LCAKUWdL', 'MipCwGTrAj', 'JnECeMCPSX' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, DikMSDzLh1GP3ebiqj.cs | High entropy of concatenated method names: 'qDrexV8BFw', 'JIwebSbjbZ', 'Svnei2mcnK', 'Y4MePdS9qh', 'n6MeBDxgll', 'DqMeF2Rv5w', 'BYWeRHZbW6', 'I6ee4mJ4C9', 'FCte6f6lSH', 'LjYeSy2JQP' |
Source: 0.2.Bank Transfer Form.exe.4909010.4.raw.unpack, GOdDuQpxLDLFynigs0.cs | High entropy of concatenated method names: 'hQJrbb9RBt', 'IYkriJrehr', 'NHQrPtUKce', 'w3irBLfbTT', 'E7prFmd3eY', 'gRsrR4dHEM', 'IQCrsBVaQ3', 'vq8rODnL5f', 'MqtrntPDlR', 'ikkro2aybS' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, YRJCD4GuTkTB5AFtUh.cs | High entropy of concatenated method names: 'sUteCUKxOF', 'aHYeYIgr7H', 'y6lefvIT1U', 'KWDe2CZ228', 'PZZewcLtKa', 'hnreqRgKGG', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, FyOPAW54oZ0b7HNW4y.cs | High entropy of concatenated method names: 'Dispose', 'U409luscwt', 'rYJkBqMk8m', 'a8al88GfCG', 'hFX9Gb9sHS', 'vgF9zP5qcW', 'ProcessDialogKey', 'iyok7A8ZRt', 'DQ2k9cNhrw', 'gCZkkGRJCD' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, WPHP2SbJjmZSALkB5D.cs | High entropy of concatenated method names: 'g0F5EsE8Ix', 'c0K5IoGB8X', 'yRK5tT8JaV', 'Cw95Lv2Rf2', 'n4m58kF2vq', 'uZq5HLNdOo', 'vqB5Vrf27o', 'jSk5WIHugE', 'EOl5lAFs5c', 'W265Gk4CB3' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, OrbTnwVH9840uscwtY.cs | High entropy of concatenated method names: 'IIqwU77tpg', 'KqtwaCr0VR', 'ti1wwI3P2W', 'khywdw3Duf', 'mqJw3llEb7', 'Cwow4GQXaq', 'Dispose', 'VZWAhW8Bb3', 'XtAA5gBYG4', 'HIjACjTA6V' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, DIv3B497lwTEGfxJNnW.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'LdgeoQj9PL', 'Qy8e00HZYo', 'pm3epIkOxU', 'yDIeEhSxhi', 'nBdeILVKnn', 'Vc0etMi0rp', 'MZTeLgZqkr' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, GK3rb8Xx6FpRmLh2PZ.cs | High entropy of concatenated method names: 'E8426mT4SH', 'QsQ2SW2wxt', 'UnO2M8H4pW', 'DUp2DdRPyM', 'qEk2vUkFBu', 'gOs2x9bYXE', 'rR22mCUorV', 'JQ02bhcOYC', 'Mft2iulPXg', 'O5D21vpN1J' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, sy4xRxkBIgUYZjXBH8.cs | High entropy of concatenated method names: 'FDHMYKxYl', 'SOADinu0w', 'y21xQRAE9', 'vZimVoS0d', 'whTi74ctC', 'JYB1NfXIE', 'kDPevhZdyn7xh0J0RH', 'pnQSHjsS4yxDye4ZZa', 'u7PALJ4ku', 'ydVe0tljk' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, cNTAxyLngQ4wmnErdU.cs | High entropy of concatenated method names: 'HHVaKngIer', 'm7jausYccb', 'ToString', 'PlZahnIi2n', 't8sa52aUEV', 'pe2aC3JocW', 'wIdaYy18LW', 'VGbafGUjqg', 'to8a2ORRY4', 'Bjcaq0P3O5' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, rSACETqoHL0qafdKnG.cs | High entropy of concatenated method names: 'nkBQJ3iqmP', 'smOQhT0OPC', 'kIoQ5eQBZJ', 'nuVQC7eJgI', 'NInQYXP5cB', 'XEPQfWnMc9', 'U0ZQ25ZRQy', 'rvkQqPXdMW', 'TYQQTMhtK9', 'j59QKhm4Ef' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, lg884FPT14t8JDBNJj.cs | High entropy of concatenated method names: 'IBqfJx6MYO', 'cHCf5orYJH', 'F6MfYThPpJ', 'SUTf2aaHO0', 'u5xfqfhXfn', 'wXAY8JZODN', 'MfoYHBfSZj', 'ORQYVKqaCt', 'OOgYWG2TPL', 'ApfYl5w9pu' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, fafNrWNPmosQBQ9Hyh.cs | High entropy of concatenated method names: 'T9W92PHP2S', 'ejm9qZSALk', 'dLQ9KeObhS', 'SfT9ufWxS9', 'h9J9UerTg8', 'U4F9jT14t8', 'hryUc55iG5GAVx4FMr', 'hbwGACznxJgtRrXIhn', 'nCK995Y4VY', 'Oq79QxfQnw' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, W0luOeHPpUUnD0Gi9F.cs | High entropy of concatenated method names: 'SwjaW25Zr4', 'OZfaGRk12k', 'KNZA7iSVf6', 'IA2A9wvvfb', 'scqaohg2os', 'wtFa03K6PC', 'BZgapUtAA2', 'OC1aE12rG0', 'kF1aIkf2rO', 'R2Fatt9krh' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, sIYM2V99T3XKebu3Mfs.cs | High entropy of concatenated method names: 'Ln5eGFQVQw', 'EEiezM3X3G', 'XwXd7VqNCh', 'zMed9CMwsV', 'rRydkFDmSs', 'E8pdQOBm7K', 'sWrdNtgnlu', 'cdXdJ1p2Ey', 'zKRdheKVn6', 'ckad5Z4nNB' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, JaYZBb9Noi2bbtHjoAV.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'XF5ywKwRrJ', 'hD8yeOFWw8', 'uCQyd08j6L', 'erQyyfb71j', 'pyZy35JuvO', 'yJIyZ7GTmb', 'AsUy4G1o5A' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, XxS9LU1e3iUikC9Jer.cs | High entropy of concatenated method names: 'noiYvJ3g4i', 'daAYmUe5HV', 'KJICgbYHZ3', 'ji8CFa0fPf', 'lRmCRtQfvt', 'TisCcV9wHB', 'skRCsp6xyR', 'HmtCOVhdIu', 'kH4CXQDJuU', 'jg7CnaG1ti' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, DgcOPfs939iFMF7LnU.cs | High entropy of concatenated method names: 'AME2hBpFvu', 'UyR2C75sWm', 'w8M2fj5Z12', 'nJpfGOBPrU', 'fd3fz8TlJC', 'DXP27Id0Fg', 'hxy29FH72S', 'pZB2kgfDsI', 'iAh2Qi3QiX', 'qTp2N0ZrBK' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, OA8ZRtlmQ2cNhrw5CZ.cs | High entropy of concatenated method names: 'YRTwPPVhbe', 'd5WwBytxQ2', 'n3bwglwFvq', 'rqowFkq3Yn', 's0vwRbXecV', 'yNRwcE5kQ4', 'LgVwskrOqf', 'XOvwOo6Nik', 'z5lwXrejEE', 'ppDwnfNKAu' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, MA9tcoCn4p8ebb7jyP.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'cRqkl7YYrM', 'aT2kGpEgd6', 'amNkzHMhTM', 'UA4Q74qZwB', 'S1EQ9uQ8K1', 'eExQk2iek6', 'YVKQQqDLj5', 'WyBRQCjIsT01lbOWdIw' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, SqAFRrEyHODwOt21AL.cs | High entropy of concatenated method names: 'CXTUnxre4x', 'YX0U0ywSWh', 'S5wUEILNgQ', 'wqEUIOxlSm', 'w5FUBS96No', 'wfWUgomDRf', 'tQUUFOG15Z', 'gSrURajbD3', 'jIuUcFDORK', 'Qh4UsMo3q3' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, L4apYNiLQeObhStfTf.cs | High entropy of concatenated method names: 'RG6CDNOs43', 'qAoCxCWgI5', 'AGvCb4m0wo', 'OvfCiVlWuW', 'XrWCU3oYYx', 'N0BCjORV62', 'Q1qCaRKuHd', 'I7LCAKUWdL', 'MipCwGTrAj', 'JnECeMCPSX' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, DikMSDzLh1GP3ebiqj.cs | High entropy of concatenated method names: 'qDrexV8BFw', 'JIwebSbjbZ', 'Svnei2mcnK', 'Y4MePdS9qh', 'n6MeBDxgll', 'DqMeF2Rv5w', 'BYWeRHZbW6', 'I6ee4mJ4C9', 'FCte6f6lSH', 'LjYeSy2JQP' |
Source: 0.2.Bank Transfer Form.exe.48817f0.3.raw.unpack, GOdDuQpxLDLFynigs0.cs | High entropy of concatenated method names: 'hQJrbb9RBt', 'IYkriJrehr', 'NHQrPtUKce', 'w3irBLfbTT', 'E7prFmd3eY', 'gRsrR4dHEM', 'IQCrsBVaQ3', 'vq8rODnL5f', 'MqtrntPDlR', 'ikkro2aybS' |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239867 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239750 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239640 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239507 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239405 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239297 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239187 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239074 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238953 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238843 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238734 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238625 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238485 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238235 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238109 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 237981 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599874 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598999 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597575 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596920 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596474 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596249 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596140 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596031 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595921 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595812 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595703 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595593 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595374 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595265 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595046 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594937 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594718 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594609 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -11068046444225724s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -240000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239867s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239507s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239405s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239297s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239187s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -239074s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238843s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238625s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -238109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7440 | Thread sleep time: -237981s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7424 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7768 | Thread sleep time: -4611686018427385s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7756 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -27670116110564310s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7792 | Thread sleep count: 1254 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7792 | Thread sleep count: 8605 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598999s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598124s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -598015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597575s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597468s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597249s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -597031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596920s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596474s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596249s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -596031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595921s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595374s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595265s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -595046s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -594937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -594828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -594718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe TID: 7788 | Thread sleep time: -594609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 240000 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239867 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239750 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239640 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239507 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239405 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239297 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239187 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 239074 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238953 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238843 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238734 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238625 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238485 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238235 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 238109 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 237981 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599874 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598999 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597575 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596920 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596474 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596359 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596249 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596140 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 596031 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595921 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595812 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595703 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595593 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595374 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595265 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 595046 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594937 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594718 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Thread delayed: delay time: 594609 | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Users\user\Desktop\Bank Transfer Form.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Users\user\Desktop\Bank Transfer Form.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Bank Transfer Form.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |