Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Argument value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "C:\\Temp\\downloaded_script.ps1"",0,true', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "C:\\Temp\\downloaded_script.ps1"",0,true', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['"WScript.Shell"', '6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "C:\\Temp\\downloaded_script.ps1"",0,true', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: Stormwater Works Drawings Spec.js | Return value : ['"WScript.Shell"', '6661216fuMSGJ,4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,', '"Scripting.FileSystemObject"', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "C:\\Temp\\downloaded_script.ps1"",0,true', '"PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File "', '4098180dQOoYH,PowerShell -NoProfile -ExecutionPolicy RemoteSigned -File ,280198hWAMOx,GET,3890340cHs'] | Go to definition |
Source: runonce.exe, 00000009.00000002.2976180128.0000000005268000.00000004.10000000.00040000.00000000.sdmp, xBjKgBCuI1jq.exe, 0000000A.00000002.2975872831.0000000003598000.00000004.00000001.00040000.00000000.sdmp | String found in binary or memory: http://cpanel.com/?utm_source=cpanelwhm&utm_medium=cplogo&utm_content=logolink&utm_campaign=404refer |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCC52A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1778622855.000001CFDAE3C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCAFF2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCADC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCAFF2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: xBjKgBCuI1jq.exe, 0000000A.00000002.2975394799.00000000029C6000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.kjuw.party |
Source: xBjKgBCuI1jq.exe, 0000000A.00000002.2975394799.00000000029C6000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.kjuw.party/e0jv/ |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCADC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: powershell.exe, 00000001.00000002.1778622855.000001CFDAE3C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000001.00000002.1778622855.000001CFDAE3C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000001.00000002.1778622855.000001CFDAE3C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: wscript.exe, 00000000.00000002.1801684145.0000023136B9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.ca |
Source: wscript.exe, 00000000.00000002.1801873166.00000231390B0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1801585342.00000231369F8000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1798831358.00000231369F3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe |
Source: wscript.exe, 00000000.00000002.1801873166.00000231390B0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/ |
Source: wscript.exe, 00000000.00000003.1691274229.00000231386CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/e |
Source: wscript.exe, 00000000.00000003.1690479875.00000231386BA000.00000004.00000020.00020000.00000000.sdmp, Stormwater Works Drawings Spec.js | String found in binary or memory: https://files.catbox.moe/et18ob.ps1 |
Source: wscript.exe, 00000000.00000003.1799104824.00000231369E7000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1798911413.00000231369DC000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1801563846.00000231369E8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/et18ob.ps1) |
Source: wscript.exe, 00000000.00000003.1800210275.00000231388B5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/et18ob.ps1D |
Source: wscript.exe, 00000000.00000003.1687859855.0000023138681000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/et18ob.ps1g2 |
Source: wscript.exe, 00000000.00000002.1801873166.00000231390B0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe/j |
Source: wscript.exe, 00000000.00000002.1801873166.00000231390B0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1801585342.00000231369F8000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1798831358.00000231369F3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://files.catbox.moe; |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCAFF2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com: |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srfclient_id=00000000480728C5&scope=service::ssl.live.com:: |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033 |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srflc=1033 |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live |
Source: runonce.exe, 00000009.00000002.2974317535.00000000026FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srfclient_id=00000000480728C5&redirect_uri=https://login.live. |
Source: runonce.exe, 00000009.00000003.2392387019.0000000007657000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srfhttps://login.live.com/oauth20_authorize.srfhttps://login.l |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCC52A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1778622855.000001CFDAE3C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.org |
Source: powershell.exe, 00000001.00000002.1741112479.000001CFCBFC7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.orgX |
Source: runonce.exe, 00000009.00000002.2977845167.0000000007668000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: xBjKgBCuI1jq.exe, 0000000A.00000002.2975872831.0000000003406000.00000004.00000001.00040000.00000000.sdmp | String found in binary or memory: https://www.seasay.xyz/c9ts/?CL=b2h4705j/BXuiRKuOXJLA/Ych4 |
Source: runonce.exe, 00000009.00000002.2976180128.0000000004F44000.00000004.10000000.00040000.00000000.sdmp, xBjKgBCuI1jq.exe, 0000000A.00000002.2975872831.0000000003274000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.2505034564.000000003A3C4000.00000004.80000000.00040000.00000000.sdmp | String found in binary or memory: https://wx.longwaysun.com/app/register.php?site_id=2239&topId=86884/vhr7/ |
Source: runonce.exe, 00000009.00000002.2976180128.0000000004F44000.00000004.10000000.00040000.00000000.sdmp, xBjKgBCuI1jq.exe, 0000000A.00000002.2975872831.0000000003274000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.2505034564.000000003A3C4000.00000004.80000000.00040000.00000000.sdmp | String found in binary or memory: https://wx.longwaysun.com/app/register.php?site_id=2239&topId=86884/vhr7/ |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0042CAA3 NtClose, | 4_2_0042CAA3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F635C0 NtCreateMutant,LdrInitializeThunk, | 4_2_00F635C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62B60 NtClose,LdrInitializeThunk, | 4_2_00F62B60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62C70 NtFreeVirtualMemory,LdrInitializeThunk, | 4_2_00F62C70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62DF0 NtQuerySystemInformation,LdrInitializeThunk, | 4_2_00F62DF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F63090 NtSetValueKey, | 4_2_00F63090 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F63010 NtOpenDirectoryObject, | 4_2_00F63010 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F64340 NtSetContextThread, | 4_2_00F64340 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F64650 NtSuspendThread, | 4_2_00F64650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F639B0 NtGetContextThread, | 4_2_00F639B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62AF0 NtWriteFile, | 4_2_00F62AF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62AD0 NtReadFile, | 4_2_00F62AD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62AB0 NtWaitForSingleObject, | 4_2_00F62AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62BF0 NtAllocateVirtualMemory, | 4_2_00F62BF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62BE0 NtQueryValueKey, | 4_2_00F62BE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62BA0 NtEnumerateValueKey, | 4_2_00F62BA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62B80 NtQueryInformationFile, | 4_2_00F62B80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62CF0 NtOpenProcess, | 4_2_00F62CF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62CC0 NtQueryVirtualMemory, | 4_2_00F62CC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62CA0 NtQueryInformationToken, | 4_2_00F62CA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62C60 NtCreateKey, | 4_2_00F62C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62C00 NtQueryInformationProcess, | 4_2_00F62C00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62DD0 NtDelayExecution, | 4_2_00F62DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62DB0 NtEnumerateKey, | 4_2_00F62DB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F63D70 NtOpenThread, | 4_2_00F63D70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62D30 NtUnmapViewOfSection, | 4_2_00F62D30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62D10 NtMapViewOfSection, | 4_2_00F62D10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F63D10 NtOpenProcessToken, | 4_2_00F63D10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62D00 NtSetInformationFile, | 4_2_00F62D00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62EE0 NtQueueApcThread, | 4_2_00F62EE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62EA0 NtAdjustPrivilegesToken, | 4_2_00F62EA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62E80 NtReadVirtualMemory, | 4_2_00F62E80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62E30 NtWriteVirtualMemory, | 4_2_00F62E30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62FE0 NtCreateFile, | 4_2_00F62FE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62FB0 NtResumeThread, | 4_2_00F62FB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62FA0 NtQuerySection, | 4_2_00F62FA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62F90 NtProtectVirtualMemory, | 4_2_00F62F90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62F60 NtCreateProcessEx, | 4_2_00F62F60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F62F30 NtCreateSection, | 4_2_00F62F30 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A35C0 NtCreateMutant,LdrInitializeThunk, | 9_2_045A35C0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A4650 NtSuspendThread,LdrInitializeThunk, | 9_2_045A4650 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A4340 NtSetContextThread,LdrInitializeThunk, | 9_2_045A4340 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2C70 NtFreeVirtualMemory,LdrInitializeThunk, | 9_2_045A2C70 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2C60 NtCreateKey,LdrInitializeThunk, | 9_2_045A2C60 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2CA0 NtQueryInformationToken,LdrInitializeThunk, | 9_2_045A2CA0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2D10 NtMapViewOfSection,LdrInitializeThunk, | 9_2_045A2D10 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2D30 NtUnmapViewOfSection,LdrInitializeThunk, | 9_2_045A2D30 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2DD0 NtDelayExecution,LdrInitializeThunk, | 9_2_045A2DD0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2DF0 NtQuerySystemInformation,LdrInitializeThunk, | 9_2_045A2DF0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2EE0 NtQueueApcThread,LdrInitializeThunk, | 9_2_045A2EE0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2E80 NtReadVirtualMemory,LdrInitializeThunk, | 9_2_045A2E80 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2F30 NtCreateSection,LdrInitializeThunk, | 9_2_045A2F30 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2FE0 NtCreateFile,LdrInitializeThunk, | 9_2_045A2FE0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2FB0 NtResumeThread,LdrInitializeThunk, | 9_2_045A2FB0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A39B0 NtGetContextThread,LdrInitializeThunk, | 9_2_045A39B0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2AD0 NtReadFile,LdrInitializeThunk, | 9_2_045A2AD0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2AF0 NtWriteFile,LdrInitializeThunk, | 9_2_045A2AF0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2B60 NtClose,LdrInitializeThunk, | 9_2_045A2B60 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2BF0 NtAllocateVirtualMemory,LdrInitializeThunk, | 9_2_045A2BF0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2BE0 NtQueryValueKey,LdrInitializeThunk, | 9_2_045A2BE0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2BA0 NtEnumerateValueKey,LdrInitializeThunk, | 9_2_045A2BA0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A3010 NtOpenDirectoryObject, | 9_2_045A3010 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A3090 NtSetValueKey, | 9_2_045A3090 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2C00 NtQueryInformationProcess, | 9_2_045A2C00 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2CC0 NtQueryVirtualMemory, | 9_2_045A2CC0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2CF0 NtOpenProcess, | 9_2_045A2CF0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A3D70 NtOpenThread, | 9_2_045A3D70 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A3D10 NtOpenProcessToken, | 9_2_045A3D10 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2D00 NtSetInformationFile, | 9_2_045A2D00 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2DB0 NtEnumerateKey, | 9_2_045A2DB0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2E30 NtWriteVirtualMemory, | 9_2_045A2E30 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2EA0 NtAdjustPrivilegesToken, | 9_2_045A2EA0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2F60 NtCreateProcessEx, | 9_2_045A2F60 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2F90 NtProtectVirtualMemory, | 9_2_045A2F90 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2FA0 NtQuerySection, | 9_2_045A2FA0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2AB0 NtWaitForSingleObject, | 9_2_045A2AB0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A2B80 NtQueryInformationFile, | 9_2_045A2B80 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02629680 NtReadFile, | 9_2_02629680 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02629780 NtDeleteFile, | 9_2_02629780 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02629510 NtCreateFile, | 9_2_02629510 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02629820 NtClose, | 9_2_02629820 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02629980 NtAllocateVirtualMemory, | 9_2_02629980 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0441F2CF NtReadVirtualMemory, | 9_2_0441F2CF |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0441F8C4 NtMapViewOfSection, | 9_2_0441F8C4 |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Code function: 3_2_011B0D61 | 3_2_011B0D61 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_004188F3 | 4_2_004188F3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00403000 | 4_2_00403000 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_004100CA | 4_2_004100CA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0042F0D3 | 4_2_0042F0D3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_004100D3 | 4_2_004100D3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00401240 | 4_2_00401240 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0040E2E3 | 4_2_0040E2E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_004102F3 | 4_2_004102F3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00416AFE | 4_2_00416AFE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00416B03 | 4_2_00416B03 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00402462 | 4_2_00402462 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00402470 | 4_2_00402470 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0040E47C | 4_2_0040E47C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0040E427 | 4_2_0040E427 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_0040E433 | 4_2_0040E433 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00402750 | 4_2_00402750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE70E9 | 4_2_00FE70E9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEF0E0 | 4_2_00FEF0E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FDF0CC | 4_2_00FDF0CC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F370C0 | 4_2_00F370C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE81CC | 4_2_00FE81CC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F3B1B0 | 4_2_00F3B1B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FF01AA | 4_2_00FF01AA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F1F172 | 4_2_00F1F172 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FFB16B | 4_2_00FFB16B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F6516C | 4_2_00F6516C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FCA118 | 4_2_00FCA118 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F20100 | 4_2_00F20100 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4D2F0 | 4_2_00F4D2F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FD12ED | 4_2_00FD12ED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4B2C0 | 4_2_00F4B2C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F352A0 | 4_2_00F352A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FD0274 | 4_2_00FD0274 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F3E3F0 | 4_2_00F3E3F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FF03E6 | 4_2_00FF03E6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F7739A | 4_2_00F7739A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEA352 | 4_2_00FEA352 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F1D34C | 4_2_00F1D34C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE132D | 4_2_00FE132D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FDE4F6 | 4_2_00FDE4F6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F21460 | 4_2_00F21460 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE2446 | 4_2_00FE2446 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEF43F | 4_2_00FEF43F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FCD5B0 | 4_2_00FCD5B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FF0591 | 4_2_00FF0591 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE7571 | 4_2_00FE7571 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F30535 | 4_2_00F30535 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4C6E0 | 4_2_00F4C6E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE16CC | 4_2_00FE16CC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F2C7C0 | 4_2_00F2C7C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEF7B0 | 4_2_00FEF7B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F30770 | 4_2_00F30770 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F54750 | 4_2_00F54750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F5E8F0 | 4_2_00F5E8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F338E0 | 4_2_00F338E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F168B8 | 4_2_00F168B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F32840 | 4_2_00F32840 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F3A840 | 4_2_00F3A840 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F9D800 | 4_2_00F9D800 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F329A0 | 4_2_00F329A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FFA9A6 | 4_2_00FFA9A6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F46962 | 4_2_00F46962 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F39950 | 4_2_00F39950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4B950 | 4_2_00F4B950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FDDAC6 | 4_2_00FDDAC6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FCDAAC | 4_2_00FCDAAC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F75AA0 | 4_2_00F75AA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F2EA80 | 4_2_00F2EA80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FA3A6C | 4_2_00FA3A6C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEFA49 | 4_2_00FEFA49 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE7A46 | 4_2_00FE7A46 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F6DBF9 | 4_2_00F6DBF9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE6BD7 | 4_2_00FE6BD7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00EF9B80 | 4_2_00EF9B80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4FB80 | 4_2_00F4FB80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEFB76 | 4_2_00FEFB76 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEAB40 | 4_2_00FEAB40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F20CF2 | 4_2_00F20CF2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEFCF2 | 4_2_00FEFCF2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FD0CB5 | 4_2_00FD0CB5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FA9C32 | 4_2_00FA9C32 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F30C00 | 4_2_00F30C00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F2ADE0 | 4_2_00F2ADE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F4FDC0 | 4_2_00F4FDC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F48DBF | 4_2_00F48DBF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE7D73 | 4_2_00FE7D73 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FE1D5A | 4_2_00FE1D5A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F33D40 | 4_2_00F33D40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F3AD00 | 4_2_00F3AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEEEDB | 4_2_00FEEEDB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F39EB0 | 4_2_00F39EB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F42E90 | 4_2_00F42E90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FECE93 | 4_2_00FECE93 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F30E59 | 4_2_00F30E59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEEE26 | 4_2_00FEEE26 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F22FC8 | 4_2_00F22FC8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00EF3FD5 | 4_2_00EF3FD5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00EF3FD2 | 4_2_00EF3FD2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEFFB1 | 4_2_00FEFFB1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F31F92 | 4_2_00F31F92 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FA4F40 | 4_2_00FA4F40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F50F30 | 4_2_00F50F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00F72F28 | 4_2_00F72F28 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe | Code function: 4_2_00FEFF09 | 4_2_00FEFF09 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04622446 | 9_2_04622446 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04561460 | 9_2_04561460 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462F43F | 9_2_0462F43F |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0461E4F6 | 9_2_0461E4F6 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04627571 | 9_2_04627571 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04570535 | 9_2_04570535 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0460D5B0 | 9_2_0460D5B0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04630591 | 9_2_04630591 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046216CC | 9_2_046216CC |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458C6E0 | 9_2_0458C6E0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04594750 | 9_2_04594750 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04570770 | 9_2_04570770 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0456C7C0 | 9_2_0456C7C0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462F7B0 | 9_2_0462F7B0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462F0E0 | 9_2_0462F0E0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046270E9 | 9_2_046270E9 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045770C0 | 9_2_045770C0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0461F0CC | 9_2_0461F0CC |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0463B16B | 9_2_0463B16B |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0455F172 | 9_2_0455F172 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045A516C | 9_2_045A516C |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04560100 | 9_2_04560100 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0460A118 | 9_2_0460A118 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046281CC | 9_2_046281CC |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046301AA | 9_2_046301AA |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0457B1B0 | 9_2_0457B1B0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04610274 | 9_2_04610274 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046112ED | 9_2_046112ED |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458B2C0 | 9_2_0458B2C0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458D2F0 | 9_2_0458D2F0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045752A0 | 9_2_045752A0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0455D34C | 9_2_0455D34C |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462A352 | 9_2_0462A352 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462132D | 9_2_0462132D |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_046303E6 | 9_2_046303E6 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0457E3F0 | 9_2_0457E3F0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045B739A | 9_2_045B739A |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04570C00 | 9_2_04570C00 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045E9C32 | 9_2_045E9C32 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462FCF2 | 9_2_0462FCF2 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04560CF2 | 9_2_04560CF2 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04610CB5 | 9_2_04610CB5 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04627D73 | 9_2_04627D73 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04573D40 | 9_2_04573D40 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04621D5A | 9_2_04621D5A |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0457AD00 | 9_2_0457AD00 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458FDC0 | 9_2_0458FDC0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0456ADE0 | 9_2_0456ADE0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04588DBF | 9_2_04588DBF |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04570E59 | 9_2_04570E59 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462EE26 | 9_2_0462EE26 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462EEDB | 9_2_0462EEDB |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04582E90 | 9_2_04582E90 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04579EB0 | 9_2_04579EB0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462CE93 | 9_2_0462CE93 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045E4F40 | 9_2_045E4F40 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04590F30 | 9_2_04590F30 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462FF09 | 9_2_0462FF09 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04562FC8 | 9_2_04562FC8 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04571F92 | 9_2_04571F92 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462FFB1 | 9_2_0462FFB1 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04572840 | 9_2_04572840 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0457A840 | 9_2_0457A840 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0459E8F0 | 9_2_0459E8F0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045738E0 | 9_2_045738E0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045568B8 | 9_2_045568B8 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04579950 | 9_2_04579950 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458B950 | 9_2_0458B950 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04586962 | 9_2_04586962 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0463A9A6 | 9_2_0463A9A6 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045729A0 | 9_2_045729A0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04627A46 | 9_2_04627A46 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462FA49 | 9_2_0462FA49 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045E3A6C | 9_2_045E3A6C |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0461DAC6 | 9_2_0461DAC6 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0460DAAC | 9_2_0460DAAC |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0456EA80 | 9_2_0456EA80 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_045B5AA0 | 9_2_045B5AA0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462FB76 | 9_2_0462FB76 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0462AB40 | 9_2_0462AB40 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_04626BD7 | 9_2_04626BD7 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0458FB80 | 9_2_0458FB80 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02611FD0 | 9_2_02611FD0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260B060 | 9_2_0260B060 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260D070 | 9_2_0260D070 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260B1F9 | 9_2_0260B1F9 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260B1A4 | 9_2_0260B1A4 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260B1B0 | 9_2_0260B1B0 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02615670 | 9_2_02615670 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0261387B | 9_2_0261387B |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_02613880 | 9_2_02613880 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260CE47 | 9_2_0260CE47 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0260CE50 | 9_2_0260CE50 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0262BE50 | 9_2_0262BE50 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0441E467 | 9_2_0441E467 |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0441E7FC | 9_2_0441E7FC |
Source: C:\Windows\SysWOW64\runonce.exe | Code function: 9_2_0441D8C8 | 9_2_0441D8C8 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_029882F7 | 10_2_029882F7 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02983397 | 10_2_02983397 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02981387 | 10_2_02981387 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02989BA2 | 10_2_02989BA2 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02989BA7 | 10_2_02989BA7 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_0298B997 | 10_2_0298B997 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_029A2177 | 10_2_029A2177 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02983177 | 10_2_02983177 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_0298316E | 10_2_0298316E |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_029814D7 | 10_2_029814D7 |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_029814CB | 10_2_029814CB |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Code function: 10_2_02981520 | 10_2_02981520 |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: ieframe.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: winsqlite3.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\runonce.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Program Files (x86)\gIREEBsbXssxtwKkMKvDTBBLViqVuETHlLrFwnWJjmjJmQXPIXTAYTbEEcuPzNzWLUcNWAXpeeWFdBGY\xBjKgBCuI1jq.exe | Section loaded: rasadhlp.dll | Jump to behavior |